Computer Security US Blog

Computer Security News and Insights

Cyber Incident Response Steps

Cyber Incident Response Steps That Actually Work

A Ransomware Attack Exposed What Most Plans Are Missing In February 2024, Change Healthcare suffered a ransomware attack that disrupted prescription processing for millions of Americans. UnitedHealth Group later confirmed the breach affected approximately 100 million individuals — the largest healthcare data breach in U.S. history. The attackers got in

Carl B. Johnson Aug 21, 2026 5 min read
Computer Security Software

Computer Security Software: What Actually Stops Breaches

A $100,000 Antivirus Setup That Stopped Nothing I worked with an organization in 2024 that had invested heavily in computer security software — endpoint detection, next-gen firewalls, SIEM, the works. They still got hit with a ransomware attack that encrypted 14,000 files and shut down operations for nine days.

Carl B. Johnson Aug 21, 2026 5 min read
Gmail Phishing Attacks

Gmail Sophisticated Attacks: FBI Phishing Warnings for 2026

A Google Developer Nearly Lost Everything to a Fake Support Call In early 2025, a well-known Google developer publicly documented how he nearly fell for a sophisticated phishing attack targeting his Gmail account. The caller ID showed a legitimate Google phone number. The voice on the other end sounded professional,

Carl B. Johnson Aug 20, 2026 6 min read
Vendor Risk Management

Vendor Risk Management Cybersecurity: A Practical Guide

The Breach That Didn't Start With You In 2023, the MOVEit Transfer vulnerability didn't just hit one company — it cascaded through thousands of organizations that trusted a single vendor's file transfer software. Clop ransomware operators exploited the flaw, and suddenly organizations like the BBC,

Carl B. Johnson Aug 20, 2026 6 min read
Fake Email

Fake Email: How to Spot One Before It Costs You

In 2019, a Lithuanian man named Evaldas Rimasauskas pleaded guilty to stealing over $100 million from Google and Facebook — using nothing more than a series of fake email messages. He impersonated a legitimate hardware vendor, sent invoices from spoofed email addresses, and two of the most sophisticated tech companies on

Carl B. Johnson Aug 19, 2026 6 min read
Social Engineering Attacks

Social Engineering Attacks: How They Actually Work

In September 2023, a threat actor called Scattered Spider social-engineered their way into MGM Resorts by calling the company's IT help desk. One phone call. That's all it took to trigger a shutdown that cost MGM an estimated $100 million. No zero-day exploit. No sophisticated malware.

Carl B. Johnson Aug 19, 2026 5 min read
NIST Standards

NIST Standards: What They Actually Mean for Your Security

The Framework Nobody Reads But Everyone Claims to Follow I once walked into a mid-sized financial firm that proudly declared on their website they were "aligned with NIST standards." Thirty minutes into the assessment, I found admin passwords on sticky notes, no multi-factor authentication on critical systems, and

Carl B. Johnson Aug 18, 2026 6 min read