Tag

Credential Theft

Posts exploring how attackers steal usernames, passwords, and authentication tokens through phishing, keylogging, brute force attacks, and credential stuffing. Includes actionable guidance on multi-factor authentication, password managers, and monitoring for compromised credentials.

posts

Fake Mailer

Fake Mailer Attacks: How Threat Actors Spoof Email

In 2023, a finance employee at a multinational firm wired $25 million after receiving what appeared to be emails from the company's CFO. The messages were convincing, urgent, and completely fabricated. The attacker used a fake mailer — a tool designed to forge the "From" field in

Carl B. Johnson Jul 17, 2026 5 min read
Phishing Emails

How Phishing Emails Work: The Psychology Behind Them

A Fake Invoice Cost One Company $121 Million In 2019, a Lithuanian national named Evaldas Rimasauskas pleaded guilty to orchestrating a phishing scheme that stole over $121 million from Google and Facebook. His weapon wasn't malware. It wasn't a zero-day exploit. It was email — and an

Carl B. Johnson Jul 14, 2026 5 min read
Phishing Scams

Phishing Scams: What They Cost and How to Stop Them

The FBI Says Phishing Scams Are the #1 Cybercrime — And It's Not Even Close In 2023, the FBI's Internet Crime Complaint Center (IC3) received over 298,000 complaints about phishing scams — more than any other cybercrime category. That number has topped the charts for five consecutive

Carl B. Johnson Jul 13, 2026 6 min read
DNS Spoofing

DNS Spoofing Attack: How Hackers Redirect Your Traffic

A Bank's Customers Were Logging In — Just Not to the Real Bank In 2017, attackers hijacked DNS records for a major Brazilian bank, redirecting all of its online customers to perfectly cloned phishing sites for roughly five hours. Every login, every transaction, every credential — harvested in real time.

Carl B. Johnson Jul 13, 2026 5 min read
Security in Cloud Computing

Security in Cloud Computing: What Goes Wrong in 2026

A Single Checkbox Left 540 Million Facebook Records Exposed Back in 2019, researchers at UpGuard discovered that two third-party Facebook app developers had stored more than 540 million user records on Amazon S3 buckets with no access restrictions. Not encrypted. Not firewalled. Just sitting there, publicly readable, because someone didn&

Carl B. Johnson Jul 09, 2026 6 min read
Man in the Middle Attack

Man in the Middle Attack: How Hackers Steal Data

In January 2024, security researchers at Checkmarx uncovered a massive man in the middle attack campaign targeting the Python Package Index (PyPI), where threat actors intercepted developer credentials and injected malicious code into software supply chains. The attack went undetected for months. This wasn't some exotic nation-state operation

Carl B. Johnson Jul 05, 2026 6 min read
VPN Best Practices

VPN Best Practices: What Actually Protects You in 2026

In early 2024, Ivanti disclosed critical vulnerabilities in its Connect Secure VPN that were already being actively exploited by threat actors — including nation-state groups. CISA issued an emergency directive ordering federal agencies to disconnect affected devices within 48 hours. If that doesn't make you rethink your VPN best

Carl B. Johnson Jul 05, 2026 5 min read