Computer Security US Blog

Computer Security News and Insights

Cyber Hygiene

Cyber Hygiene Definition: What It Really Means in 2026

A Hospital Paid $475,000 Because Someone Skipped the Basics In 2023, the U.S. Department of Health and Human Services settled with a healthcare provider for $475,000 after a phishing attack exposed patient records. The root cause wasn't a sophisticated zero-day exploit. It was a lack

Carl B. Johnson Aug 09, 2026 5 min read
Cybersecurity Tips

Cybersecurity Tips That Actually Stop Breaches in 2026

A single employee at MGM Resorts answered a phone call from someone pretending to be a coworker. That one social engineering attack in September 2023 led to roughly $100 million in losses, a crippled reservation system, and slot machines going dark across Las Vegas. The attacker didn't exploit

Carl B. Johnson Aug 09, 2026 5 min read
Ransomware

How Ransomware Spreads: 6 Attack Vectors in 2026

A Single Email Took Down a $5.8 Billion Pipeline In May 2021, a single compromised password shut down Colonial Pipeline and triggered fuel shortages across the U.S. East Coast. The attack didn't start with some exotic zero-day exploit. It started with a stolen credential and an

Carl B. Johnson Aug 08, 2026 6 min read
Strong Password Examples

Strong Password Examples That Actually Stop Hackers

The 11-Billion-Record Wake-Up Call In January 2024, researchers discovered a file called "RockYou2024" containing nearly 10 billion unique plaintext passwords compiled from decades of data breaches. That's not a typo. Billions of passwords — many still in active use — sitting in a downloadable text file. If you&

Carl B. Johnson Aug 08, 2026 5 min read
AI Phishing Attacks

Gmail Users Warned About Sophisticated AI-Driven Phishing

The AI-Generated Email That Fooled a Security Engineer In early 2025, a Google Workspace consultant named Sam Mitrovic publicly documented how he nearly fell for an AI-driven phishing attack targeting his Gmail account. The attacker spoofed Google's support number, used a perfectly natural AI-generated voice, and referenced real

Carl B. Johnson Aug 08, 2026 6 min read
Spoofing Caller

Spoofing Caller Attacks: How Criminals Fake Their Way In

In 2023, the FBI's Internet Crime Complaint Center reported over 43,000 victims of spoofing-related fraud, with losses exceeding $300 million. That number has only climbed since. And here's the part that should keep you up at night: a spoofing caller doesn't need malware,

Carl B. Johnson Aug 07, 2026 6 min read
Computer Security Advice

Computer Security Advice That Actually Works in 2026

A school district in Arizona lost $3.5 million in January 2024 after a single employee followed spoofed wire transfer instructions. The attacker didn't exploit a software vulnerability. They exploited trust. That incident captures why most computer security advice fails — it focuses on tools while ignoring the human

Carl B. Johnson Aug 07, 2026 5 min read
Password Hygiene Tips

Password Hygiene Tips That Actually Stop Breaches

The Breach That Started With "Spring2024!" In 2023, a Verizon Data Breach Investigations Report finding shook the industry: roughly 49% of breaches involved stolen credentials. Not sophisticated zero-day exploits. Not nation-state malware. Passwords. Reused, predictable, phishable passwords. I've responded to incidents where the root cause was

Carl B. Johnson Aug 06, 2026 5 min read
Cloud Storage Security Risks

Cloud Storage Security Risks: What Your Team Ignores

In January 2024, Microsoft disclosed that a Russian state-sponsored threat actor — Midnight Blizzard — breached corporate email accounts by exploiting a legacy test tenant that lacked multi-factor authentication. No zero-day exploit. No sophisticated malware. Just a password spray against a forgotten cloud account. That single oversight gave attackers months of access

Carl B. Johnson Aug 06, 2026 5 min read