Tag

Security Awareness Training

Discover resources and strategies for building effective security awareness training programs. Posts cover curriculum design, engagement techniques, compliance requirements, and methods for measuring training impact to reduce human-related security incidents across organizations.

posts

Fake Mailer

Fake Mailer Attacks: How Threat Actors Spoof Email

In 2023, a finance employee at a multinational firm wired $25 million after receiving what appeared to be emails from the company's CFO. The messages were convincing, urgent, and completely fabricated. The attacker used a fake mailer — a tool designed to forge the "From" field in

Carl B. Johnson Jul 17, 2026 5 min read
Home Computer Security

How Can You Protect Your Home Computer in 2026

Your Home Computer Is a Bigger Target Than You Think In 2023, the FBI's Internet Crime Complaint Center received over 880,000 complaints with losses exceeding $12.5 billion — and a massive share of those victims were everyday people targeted through their personal machines. Not corporate networks. Not

Carl B. Johnson Jul 16, 2026 5 min read
Ransomware

What Is Ransomware? A Security Pro's Real-World Guide

A Hospital Goes Dark in 90 Seconds In 2024, Change Healthcare — one of the largest health payment processors in the United States — was hit by the ALPHV/BlackCat ransomware group. The attack disrupted pharmacy operations, delayed patient care, and exposed the protected health information of roughly 100 million individuals. UnitedHealth

Carl B. Johnson Jul 16, 2026 5 min read
Ransomware Prevention

How to Prevent Ransomware: A Practical Defense Guide

A Single Click Cost One Hospital Chain $100 Million In 2024, Change Healthcare — one of the largest health payment processors in the U.S. — got hit with a ransomware attack that disrupted pharmacy operations across the entire country. UnitedHealth Group, its parent company, reported costs exceeding $870 million related to

Carl B. Johnson Jul 16, 2026 5 min read
Password Security

Password Security Best Practices That Stop Breaches

The 2024 Verizon Data Breach Investigations Report found that stolen credentials were involved in 77% of attacks against web applications. Let me restate that: more than three out of four web app breaches started with a compromised password. Despite billions spent on perimeter defenses, password security best practices remain the

Carl B. Johnson Jul 15, 2026 5 min read
Strong Passwords

Strong Password Examples That Actually Stop Hackers

In 2023, a single reused password led to the MGM Resorts breach that cost the company over $100 million in damages. The threat actor didn't exploit a zero-day vulnerability or write custom malware. They called the help desk, social-engineered their way in, and leveraged weak credentials to move

Carl B. Johnson Jul 13, 2026 5 min read
Phishing Scams

Phishing Scams: What They Cost and How to Stop Them

The FBI Says Phishing Scams Are the #1 Cybercrime — And It's Not Even Close In 2023, the FBI's Internet Crime Complaint Center (IC3) received over 298,000 complaints about phishing scams — more than any other cybercrime category. That number has topped the charts for five consecutive

Carl B. Johnson Jul 13, 2026 6 min read
DNS Spoofing

DNS Spoofing Attack: How Hackers Redirect Your Traffic

A Bank's Customers Were Logging In — Just Not to the Real Bank In 2017, attackers hijacked DNS records for a major Brazilian bank, redirecting all of its online customers to perfectly cloned phishing sites for roughly five hours. Every login, every transaction, every credential — harvested in real time.

Carl B. Johnson Jul 13, 2026 5 min read
Password Security Best Practices

Password Security Best Practices That Stop Breaches

The 10-Billion-Password Wake-Up Call In July 2024, a file called "RockYou2024" appeared on a popular hacking forum containing nearly 10 billion unique plaintext passwords compiled from decades of data breaches. It was the largest credential compilation ever leaked. Within weeks, threat actors were running those passwords against corporate

Carl B. Johnson Jul 12, 2026 5 min read