Tag

Network Security

Covers strategies, tools, and best practices for protecting computer networks from unauthorized access, cyberattacks, and data breaches. Topics include firewalls, intrusion detection systems, network segmentation, and monitoring techniques that help organizations maintain secure and resilient infrastructure.

posts

Zero Trust Network Access

Zero Trust Network Access: What It Actually Takes

In 2023, the U.S. Marshals Service suffered a major breach when a threat actor compromised a system containing sensitive law enforcement data — personal information on investigative targets, internal processes, and more. The agency had traditional perimeter defenses in place. What they didn't have was a model that

Carl B. Johnson Oct 04, 2026 5 min read
Zero Trust Security Model

Zero Trust Security Model: Why Perimeters Are Dead

In January 2024, Microsoft disclosed that a Russian threat actor group known as Midnight Blizzard had accessed senior executive email accounts — not by exploiting some exotic zero-day, but by spray-attacking a legacy test account that lacked multi-factor authentication. One account. No MFA. That's all it took to breach

Carl B. Johnson Oct 03, 2026 5 min read
Remote Desktop Security Risks

Remote Desktop Security Risks Your Team Ignores Daily

3389: The Port That Keeps Giving — to Attackers In 2023, the FBI's Internet Crime Complaint Center flagged Remote Desktop Protocol (RDP) as the single most common initial access vector in ransomware incidents reported to law enforcement. Not phishing. Not USB drives. RDP. And yet, in 2026, I still

Carl B. Johnson Sep 30, 2026 6 min read
VPN Best Practices

VPN Best Practices: What Actually Protects You in 2026

In 2024, Ivanti disclosed critical vulnerabilities in its VPN appliances — CVE-2024-21887 and CVE-2023-46805 — that were actively exploited by threat actors before patches were available. CISA issued an emergency directive ordering federal agencies to disconnect affected devices within 48 hours. That's not a drill. That's your VPN

Carl B. Johnson Sep 24, 2026 5 min read
Man in the Middle Attack

Man in the Middle Attack: How Hackers Steal Data

In January 2024, the FBI's Internet Crime Complaint Center flagged business email compromise — much of it powered by man in the middle attack techniques — as responsible for over $2.9 billion in adjusted losses during 2023 alone. That number isn't slowing down. I've investigated

Carl B. Johnson Sep 17, 2026 6 min read
DNS Spoofing Attack

DNS Spoofing Attack: How Hackers Hijack Your Traffic

In April 2022, researchers at Tsinghua University and the University of California disclosed a new class of DNS cache poisoning vulnerabilities affecting major DNS software. The attack, dubbed "MaginotDNS," could redirect users from legitimate banking and email sites to pixel-perfect phishing pages — and the victims never saw a

Carl B. Johnson Sep 07, 2026 6 min read
Trojan Horse Malware

Trojan Horse Malware: What It Really Does to Networks

In 2023, the FBI's Internet Crime Complaint Center reported over $12.5 billion in losses from cybercrime — and a staggering percentage of those incidents started with a single piece of software pretending to be something it wasn't. Trojan horse malware remains one of the most effective

Carl B. Johnson Sep 05, 2026 5 min read
Remote Desktop Security Risks

Remote Desktop Security Risks: What's Actually Exposed

In early 2024, Change Healthcare — one of the largest health payment processors in the United States — was brought to its knees by the ALPHV/BlackCat ransomware group. The initial entry point? A Citrix remote access portal without multi-factor authentication. That single vulnerability led to the exfiltration of data affecting roughly

Carl B. Johnson Aug 28, 2026 5 min read
DNS Spoofing Attack

DNS Spoofing Attack: How Hackers Redirect Your Traffic

Your Employees Typed the Right URL — And Still Got Hacked In April 2022, researchers at Avast documented a campaign where a threat actor compromised home routers and used DNS hijacking to redirect users from legitimate banking sites to pixel-perfect phishing clones. Victims typed the correct URL into their browser. Their

Carl B. Johnson Aug 25, 2026 6 min read
Zero Trust Implementation

Zero Trust Implementation: A Practical Guide for 2026

In January 2024, Microsoft disclosed that a Russian state-sponsored threat actor — the group known as Midnight Blizzard — breached corporate email accounts by exploiting a legacy test tenant that lacked multi-factor authentication. Microsoft. One of the most well-resourced technology companies on the planet. If they can get caught with a gap

Carl B. Johnson Aug 23, 2026 6 min read