Tag: Malware
-

Ransomware Payout: The Reality Check
Sophos says 29 percent of victims paid in 2024, down from 46 percent in 2022. Coveware says the average payment in early 2026 is around 200,000 dollars. The story is not the headline number, it is what is sitting underneath it.
-

Inside a Modern Ransomware Attack
Modern ransomware is not a virus. It is a business process. The attackers run it like a company, with departments, SLAs, and customer support for the victims.
-

Hardware Firmware Extraction in 2026
The hardware firmware extraction in 2026 sits as the security research technique the attacker uses to find the vulnerabilities the defender does not know about. The attacker extracts the firmware from the device, the attacker analyses the firmware, the attacker finds the backdoor the manufacturer left, the attacker finds the hardcoded credential the developer forgot,…
-

DDoS Mitigation on a Budget
The DDoS attack in 2026 amounts to the attack the typical enterprise faces 5-20 times per year, with the attack peaking at 1-10 Tbps, with the attack lasting 1-24 hours, with the attack costing the enterprise $20K-$200K per hour in lost revenue. The mitigation in 2026 amounts to the work the typical enterprise does on…
-

Malware in Mobile Apps in 2026
Mobile app malware in 2026 sits as the threat the typical enterprise has not addressed, with the enterprise security program focused on the endpoint, the network, the cloud, with the mobile app sitting outside the security program. The mobile app sits as the app the employee uses for the work, the app the customer uses…
-

Phishing Statistics 2026: What the Numbers Actually Look Like
The phishing statistics in 2026 run worse than the phishing statistics in 2020 on every measure that matters. The volume went up, the click through rate went up, the credential capture rate went up, the time to first click went down, the time to first report went up. The state of the phishing problem in…
-

A Field Guide to the Zero Trust Rollout
Zero trust in 2026 stands as the security framework that has been overhyped for a decade and that has finally started to deliver on the value. The 2026 zero trust rollout looks like the maturity of the tooling, the maturity of the standards, the maturity of the patterns, the maturity of the operational practice. The…
-

The Internet’s Biggest Security Problem Isn’t AI. It’s Forgotten Infrastructure
The loudest story in security is AI. The quietest one is the same problem we have had for twenty years: someone forgot to turn off a server.
-

Malware in the Open Source Supply Chain Is Now the Default
The malicious npm package, the typosquatted PyPI release, the compromised Docker image. The pattern has matured. The frequency has increased. The defence has not kept up.
-

Modern Phishing as a Service Is Boring (And That Is Why It Works)
Phishing in 2026 is not a clever technical exploit. Phishing in 2026 is a service industry, a well oiled business, and the most reliable way into a corporate network. Here is why it works.