Tag: Passwords
-

A Field Guide to the Supply Chain Attack
The supply chain attack in 2026 sits as the dominant attack pattern in the typical enterprise breach, with the attacker compromising the vendor, the vendor distributing the malicious update, the enterprise installing the update, the enterprise getting breached. The SolarWinds, the 3CX, the xz utils near miss, the 2024 Snowflake credential theft, all the same…
-

Hardware Tokens: The Quiet Comeback
The hardware token in 2026 has made a quiet comeback, with the YubiKey, the Titan, the Feitian all seeing the adoption that the push notification lost, with the hardware token sitting as the authentication that cannot be phished, that cannot be bypassed, that cannot be social engineered. The 2026 guide covers why the hardware token…
-

Lateral Movement Without Exploits in 2026
Lateral movement without exploits in 2026 amounts to the dominant attack pattern in the typical enterprise breach. The attacker compromises one endpoint with a phishing email, the attacker uses the legitimate credentials the phishing email captured, the attacker moves to the next endpoint with the legitimate credentials, the attacker does not need a single exploit…
-

The Passkey Rollout That Actually Worked
The passkey rollouts that actually worked in 2026 share the same pattern: the platform support sits in place, the user experience runs as smooth, the help desk runs ready, the metrics run visible. The rollouts that failed share the opposite pattern. The 2026 field guide covers what the working rollout looks like, what the failed…
-

Phishing Resistant MFA Deep Dive
Passwords died somewhere around 2022. The funeral for SMS codes happened in 2024. The survivors in 2026 sit at three: hardware keys, passkeys, certificate based auth. The choice between them runs as the choice the enterprise has been postponing for three years, and the postponement has cost enough breaches to retire the debate.
-

Hardware Firmware Extraction in 2026
The hardware firmware extraction in 2026 sits as the security research technique the attacker uses to find the vulnerabilities the defender does not know about. The attacker extracts the firmware from the device, the attacker analyses the firmware, the attacker finds the backdoor the manufacturer left, the attacker finds the hardcoded credential the developer forgot,…
-

SSH Key Management: The Honest Guide
A field guide to SSH key management in 2026, with the inventory problem, the rotation problem, the trust problem, and the right way to actually manage the SSH keys in a production environment.
-

The Secrets Rotation Playbook
A field guide to secrets rotation in 2026, with what the right cadence is, what to rotate and what to retire, and the automation that makes the rotation actually happen without breaking the production.
-

The Quiet Death of Passwords
The password is dying. Not in a flashy way. In a slow, decade-long, regulatory-driven way that most users will not notice until one day they realize they have not typed a password in a year.
-

Password Reuse Is Still Winning in 2026
Password reuse is still winning in 2026. People reuse passwords. They reuse the same password across work and personal accounts. They reuse the same password across the work accounts of every job they have ever had. The advice to use unique passwords is good advice. The advice is not being followed. The attackers know.