Tag

Endpoint Security

Comprehensive resources on securing laptops, desktops, mobile devices, and other endpoints that connect to your network. Covers endpoint detection and response tools, device hardening, patch management, encryption, and policies that minimize the attack surface across distributed environments.

posts

Adware vs Spyware

Adware vs Spyware: What Security Teams Must Know

In 2023, a small accounting firm in Ohio discovered that a browser toolbar one employee installed — what looked like a harmless coupon finder — had been silently logging keystrokes and exfiltrating client tax records for eleven months. The toolbar was adware on the surface. Underneath, it was spyware. And the firm

Carl B. Johnson Aug 13, 2026 6 min read
Defense Evasion

When Attackers Removed Legitimate Software to Own You

They Didn't Just Bypass Your Security — They Removed Legitimate Tools Entirely In early 2024, a ransomware gang hit a mid-sized healthcare network and encrypted 11,000 endpoints in under four hours. The forensic report revealed something chilling: before deploying a single payload, the attackers methodically removed legitimate security

Carl B. Johnson Aug 10, 2026 5 min read
Keylogger Attack

Keylogger Attack: How Hackers Steal Every Keystroke

In 2023, the FBI's IC3 received over 21,000 complaints related to malware infections that led directly to credential theft — and a significant number of those involved keyloggers silently recording every password, credit card number, and private message typed on a compromised machine. A keylogger attack doesn'

Carl B. Johnson Aug 04, 2026 5 min read
Types of Malware

Types of Malware: What Every Organization Must Know

In 2023, the FBI's Internet Crime Complaint Center received over 880,000 complaints with potential losses exceeding $12.5 billion — a 22% increase from the previous year. A staggering number of those incidents involved some form of malicious software. Understanding the types of malware your organization faces isn&

Carl B. Johnson Aug 04, 2026 5 min read
Computer Virus Prevention

Computer Virus Prevention: 9 Steps That Actually Work

In 2023, the FBI's Internet Crime Complaint Center received over 880,000 complaints with losses exceeding $12.5 billion — a 22% increase from the prior year. A significant portion of those complaints involved malware, ransomware, and credential theft that started with a single computer virus. If you think

Carl B. Johnson Aug 03, 2026 5 min read
Computer Virus Prevention

Computer Virus Prevention: 9 Steps That Actually Work

The Virus That Cost a Hospital $65 Million In 2017, the WannaCry ransomware tore through the UK's National Health Service, locking down systems at over 80 organizations and forcing hospitals to divert ambulances. The estimated cost exceeded £92 million. The root cause? Unpatched Windows machines running a known

Carl B. Johnson Jul 06, 2026 5 min read
Types of Malware

Types of Malware: What Every Organization Must Know

In 2023, MGM Resorts lost an estimated $100 million after a social engineering attack opened the door to ransomware that crippled casino floors, hotel check-ins, and digital room keys for days. The attackers didn't use some exotic, never-before-seen weapon. They used well-known types of malware — the same categories

Carl B. Johnson Jul 02, 2026 5 min read
Keylogger Attack

Keylogger Attack: How Hackers Steal Every Keystroke

In 2023, the FBI dismantled a cybercriminal operation that used the Snake malware — a sophisticated keylogger that had quietly exfiltrated credentials from government networks across 50 countries for nearly two decades. Every password. Every internal message. Every classified document typed into a keyboard. That's the reality of a

Carl B. Johnson Jun 28, 2026 5 min read
Mobile Device Security Policy

Mobile Device Security Policy: Build One That Works

A Single Lost Phone Cost This Company $4.9 Million In 2023, a healthcare organization reported a breach to HHS that started with one unencrypted smartphone left in an airport lounge. Patient records, internal credentials, VPN configurations — all exposed. The settlement and remediation costs were staggering. And here's

Carl B. Johnson Jun 18, 2026 6 min read
BYOD Security Risks

BYOD Security Risks: What Your Policy Is Missing

In 2023, a single employee's personal phone led to one of the most damaging casino breaches in history. Threat actors used social engineering to compromise MGM Resorts, and the attack vector started with a device the company didn't fully control. The resulting disruption cost MGM over

Carl B. Johnson Jun 08, 2026 5 min read