Tag

Security Awareness Training

Discover resources and strategies for building effective security awareness training programs. Posts cover curriculum design, engagement techniques, compliance requirements, and methods for measuring training impact to reduce human-related security incidents across organizations.

posts

Cloud Storage Security Risks

Cloud Storage Security Risks Your Team Is Ignoring

A Single Misconfigured S3 Bucket Exposed 540 Million Facebook Records Back in 2019, researchers at UpGuard discovered that two third-party Facebook app developers had left hundreds of millions of user records sitting in publicly accessible Amazon S3 buckets. No hacking required. No sophisticated exploit. Just wide-open cloud storage that anyone

Carl B. Johnson Jun 10, 2026 5 min read
Ransomware Examples 2026

Ransomware Examples 2026: Attacks Reshaping Security

The Ransom Note Has Changed — And So Should Your Defenses In January 2026, the FBI's Internet Crime Complaint Center (IC3) warned that ransomware complaints surged again year over year, with losses from reported incidents climbing into the billions. If you think ransomware peaked a few years ago, I

Carl B. Johnson Jun 09, 2026 5 min read
PayPal DocuSign Phishing

PayPal DocuSign Phishing: How Attackers Exploit Trust

A Legitimate Invoice From PayPal — That's Also a Scam In late 2024, security researchers at Avanan documented a campaign where threat actors sent real PayPal invoices to victims — not spoofed emails, not lookalike domains, but actual invoices generated through PayPal's own platform. The emails passed every

Carl B. Johnson Jun 09, 2026 5 min read
BYOD Security Risks

BYOD Security Risks: What Your Policy Is Missing

In 2023, a single employee's personal phone led to one of the most damaging casino breaches in history. Threat actors used social engineering to compromise MGM Resorts, and the attack vector started with a device the company didn't fully control. The resulting disruption cost MGM over

Carl B. Johnson Jun 08, 2026 5 min read
Spear Phishing

Spear Phishing: Why Targeted Attacks Beat Your Defenses

The Email That Cost One Company $100 Million In 2024, the FBI's Internet Crime Complaint Center reported that business email compromise — a form of spear phishing — accounted for over $2.9 billion in adjusted losses. That wasn't a typo. Billions. And those are just the cases

Carl B. Johnson Jun 07, 2026 5 min read
Stolen Credentials

Stolen Credentials Dark Web: How Your Logins Get Sold

In 2024, the FBI's Internet Crime Complaint Center reported losses exceeding $16 billion from cybercrime — and compromised credentials were the gateway for a staggering number of those incidents. Right now, billions of username-and-password combinations sit on dark web marketplaces, priced anywhere from $1 to $500 depending on what

Carl B. Johnson Jun 05, 2026 5 min read
Ransomware

How Ransomware Spreads: 7 Paths Into Your Network

In February 2024, Change Healthcare — the largest medical claims processor in the United States — was hit by the ALPHV/BlackCat ransomware group. The attack disrupted billing systems at hospitals and pharmacies nationwide for weeks. The entry point? Stolen credentials used on a remote access portal that lacked multi-factor authentication. One

Carl B. Johnson Jun 05, 2026 5 min read
Computer Virus Prevention

Computer Virus Prevention: 9 Steps That Actually Work

A Single Click Cost One Hospital $28 Million In 2024, Change Healthcare — a unit of UnitedHealth Group — suffered a ransomware attack that started with compromised credentials and insufficient access controls. The fallout disrupted healthcare claims across the United States for weeks. The company paid a $22 million ransom, and total

Carl B. Johnson Jun 04, 2026 5 min read
Zero Trust

What Is Zero Trust? A Security Model That Actually Works

In 2020, threat actors compromised SolarWinds' Orion software and used it to breach dozens of U.S. government agencies. The attackers moved laterally through networks for months because once they were inside the perimeter, those networks trusted them. That single breach rewrote how the federal government thinks about network

Carl B. Johnson Jun 03, 2026 5 min read