Carl B. Johnson
Author

Carl B. Johnson

vCISO and compliance expert.

https://carlbjohnson.com

posts

Cross-Site Scripting

Cross-Site Scripting Explained: A Practical Guide

In September 2024, a security researcher discovered a stored cross-site scripting vulnerability in a major email platform that allowed attackers to execute arbitrary JavaScript the moment a victim opened a crafted message. No clicks required beyond reading the email. The vulnerability sat unpatched for weeks. If you think XSS is

Carl B. Johnson Dec 10, 2024 8 min read
Phishing Awareness

How to Spot a Phishing Email Before It Costs You

In January 2024, a finance employee at a multinational firm in Hong Kong joined what appeared to be a routine video call with the company's CFO. Everything looked normal — the CFO's face, voice, and mannerisms were all spot-on. The employee followed instructions and wired $25 million

Carl B. Johnson Dec 10, 2024 7 min read
Phishing

What Is Phishing? A Security Pro's Real-World Guide

In January 2024, a finance employee at a multinational engineering firm in Hong Kong wired $25.6 million to threat actors after a video call with what appeared to be the company's CFO and several colleagues. Every person on that call was a deepfake. The attack started with

Carl B. Johnson Dec 10, 2024 7 min read
Medusa Ransomware

Medusa Ransomware Gang Phishing Campaigns Explained

A $100,000 Ransom Demand Starts With One Email In early 2024, the FBI and CISA issued a joint advisory warning that the Medusa ransomware gang had compromised over 300 organizations across critical infrastructure sectors since June 2021. The attack chain almost always starts the same way: phishing campaigns targeting

Carl B. Johnson Nov 07, 2024 7 min read
Phish

Phish: Why One Click Still Causes Million-Dollar Breaches

In January 2024, a finance employee at engineering firm Arup received an email inviting them to a video call with the company's CFO. Everything looked legitimate — the email, the meeting link, even the faces on the screen. It was all a deepfake-powered phish. That single interaction cost Arup

Carl B. Johnson Nov 07, 2024 7 min read
Fake Email

Fake Email: How to Spot, Stop, and Survive One

In January 2024, a finance worker at British engineering firm Arup was tricked into wiring $25 million to criminals after a video call — a call that started with a single fake email. The message looked like it came from the company's CFO. Everything about it — the sender name,

Carl B. Johnson Oct 17, 2024 8 min read
Phishing

Phishing in 2024: The Attack Vector That Refuses to Die

$4.88 Million Per Breach — and Phishing Opens the Door In January 2024, a finance worker at multinational firm Arup sent $25 million to threat actors after a deepfake video call that impersonated company executives. The attack started with a single phishing email. One message. Twenty-five million dollars gone. That

Carl B. Johnson Oct 17, 2024 7 min read