Computer Security US Blog

Computer Security News and Insights

Phishing Training for Employees

Phishing Training for Employees: What Actually Works

One Click Cost This Company $47 Million In 2023, a finance employee at Clorox received what looked like a routine vendor email. One click later, threat actors had a foothold inside the network. The resulting cyberattack disrupted operations for months and cost the company an estimated $356 million in damages

Carl B. Johnson Aug 14, 2026 5 min read
Data Breach Response Plan

Data Breach Response Plan: Build One Before You Need It

The Breach That Proved Most Plans Are Fiction When Uber disclosed in 2022 that it had concealed a 2016 breach affecting 57 million users — and that its former CSO had been convicted of federal obstruction charges for the cover-up — it exposed something uglier than the breach itself. The company had

Carl B. Johnson Aug 14, 2026 5 min read
Adware vs Spyware

Adware vs Spyware: What Security Teams Must Know

In 2023, a small accounting firm in Ohio discovered that a browser toolbar one employee installed — what looked like a harmless coupon finder — had been silently logging keystrokes and exfiltrating client tax records for eleven months. The toolbar was adware on the surface. Underneath, it was spyware. And the firm

Carl B. Johnson Aug 13, 2026 6 min read
Data Breach Notification

Data Breach Notification Requirements: A 2026 Guide

In February 2024, Change Healthcare suffered a ransomware attack that exposed the protected health information of roughly 100 million Americans. The fallout wasn't just technical — it was a regulatory nightmare. State attorneys general demanded answers. Congressional hearings followed. And organizations downstream from the breach scrambled to figure out

Carl B. Johnson Aug 12, 2026 6 min read
FBI Gmail

FBI Gmail Warning: What You Must Do Right Now

The FBI Just Told 1.8 Billion Gmail Users to Pay Attention When the FBI issues a public warning about a specific email platform, it's not a drill. Over the past year, the FBI has repeatedly flagged Gmail as a primary target for sophisticated phishing campaigns, AI-generated social

Carl B. Johnson Aug 12, 2026 6 min read
Data Breach Notification Requirements

Data Breach Notification Requirements: What You Owe

23andMe Proved That Getting Breached Is Bad — But Notifying Wrong Is Worse In late 2023, 23andMe disclosed a breach affecting nearly 7 million users. The breach itself was devastating. But the company's notification missteps — delayed disclosures, shifting blame to users, and inconsistent communications across jurisdictions — turned a security

Carl B. Johnson Aug 11, 2026 6 min read
Medusa Ransomware

Medusa Ransomware Gang Phishing Campaigns: What to Know

The Ransomware Gang That Treats Phishing Like a Business In March 2025, CISA and the FBI issued a joint advisory — AA25-071A — warning that the Medusa ransomware gang had compromised over 300 organizations across critical infrastructure sectors. Healthcare, education, legal, insurance, manufacturing. The attack vector in the vast majority of cases?

Carl B. Johnson Aug 11, 2026 5 min read
Defense Evasion

When Attackers Removed Legitimate Software to Own You

They Didn't Just Bypass Your Security — They Removed Legitimate Tools Entirely In early 2024, a ransomware gang hit a mid-sized healthcare network and encrypted 11,000 endpoints in under four hours. The forensic report revealed something chilling: before deploying a single payload, the attackers methodically removed legitimate security

Carl B. Johnson Aug 10, 2026 5 min read
Strong Password Examples

Strong Password Examples That Actually Stop Hackers

The 10-Character Password That Cost a Hospital $3 Million In 2023, CommonSpirit Health disclosed a ransomware attack that disrupted operations across multiple states. Investigators traced the initial access back to compromised credentials — a password that met the organization's minimum requirements but crumbled under a credential stuffing attack. The

Carl B. Johnson Aug 10, 2026 5 min read