Human Security Business Email Compromise: the costliest scam
BEC is one of the most expensive scams for companies. We explain how invoice fraud and the 'urgent CEO transfer' work — and how to stop them.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Human Security BEC is one of the most expensive scams for companies. We explain how invoice fraud and the 'urgent CEO transfer' work — and how to stop them.
Cybersecurity History In 1966, a simple program posing as a psychotherapist made people confide in him as if they were a human being - even though he didn't understand anything. The story of ELIZA and the effect that explains today's AI.
Cybersecurity History In 2016, the Mirai botnet compromised hundreds of thousands of IoT devices with default passwords and cut off Twitter, Netflix and Reddit in a single attack. The history of the cam army and its creators.
Careers and Certifications OSCP+, PNPT and CPTS differ in format, time, reporting and technical emphasis. Compare practical exams and choose the right pentester path.
AI Security Issues, comments and build logs can hijack pipeline agents. Separate untrusted content from secrets, write access, merges and artifact publishing.
Threats and Incidents A ransomware attack on Conduent exposed data on 62M+ people. What it says about third-party risk and what to do when a processor holds your data.
Identity and Access MFA is the cheapest risk reduction we know — but only when deployed well. The differences between methods, a staged rollout plan and common traps.
Cybersecurity History In 1997, an IBM computer defeated a world chess champion for the first time. The story of brute force computing, the movement that broke Kasparov, and what it meant for AI.
Threats and Incidents Infostealers are the most common malware stealing passwords, cookies and wallets. How they infect, why they bypass MFA and how to protect yourself.
Supply Chain Security A single dependency can compromise thousands of companies at once. We explain how supply chain attacks work and how to limit dependency risk.
Threats and Incidents Ransomware attacks rarely start with encryption. We break the attack chain into its parts and show where it's cheapest to break it.
Threats and Incidents A backup nobody has tested is just an assumption. The 3-2-1 rule, immutable copies that survive ransomware and restores that actually work.
Human Security An intensive campaign impersonates BLIK using SMS spoofing and fake login panels. We show how criminals take over online banking and how to break the chain.
Penetration Testing and AppSec WordPress powers most of the web and is the top target for attacks. Ten practical steps to secure your site — no coding knowledge required.
Cloud, Infrastructure and DevSecOps Kubernetes gives huge flexibility and an equally large attack surface. We cover the most common mistakes — RBAC, secrets, networking — and hardening priorities.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.