Tag

System Hardening

Techniques and strategies for reducing the attack surface of operating systems, servers, applications, and network devices. Covers configuration baselines, disabling unnecessary services, applying security patches, and implementing least-privilege principles to strengthen defenses.

posts

Security for System

Security for System Environments: A 2025 Field Guide

The Breach That Started With a Single Unpatched System In February 2024, UnitedHealth Group's subsidiary Change Healthcare suffered a ransomware attack that disrupted healthcare payment processing across the United States for weeks. The attackers gained access through a Citrix remote access portal that lacked multi-factor authentication. One system.

Carl B. Johnson Nov 06, 2025 7 min read
Security for System

Security for System Hardening: A Practical Guide

In February 2024, a misconfigured system at Change Healthcare led to one of the most devastating ransomware attacks in U.S. healthcare history. The ALPHV/BlackCat group exploited a Citrix remote access portal that lacked multi-factor authentication — a basic security for system control that should have been in place years

Carl B. Johnson Jul 10, 2024 7 min read
Security for System Administrators

Security for System Administrators: A 2026 Field Guide

The Breach That Started With a Single Unpatched Server In 2023, the MOVEit Transfer vulnerability (CVE-2023-34362) let the Cl0p ransomware gang compromise thousands of organizations worldwide — including federal agencies and major financial institutions. The root cause wasn't exotic malware or a sophisticated zero-day chain. It was a known

Carl B. Johnson Feb 25, 2019 7 min read