Tag: Passwords
-

The Incident Responder’s Playbook When Malware Hits
The first 60 minutes of a malware incident decide the next 60 days. Here is what the responder actually does, in order, with the tooling that holds up under pressure.
-

A Field Guide to Securing the IT Help Desk
The IT help desk has become the primary attack surface for the social engineering threat. The attacker calls, pretends to be an employee, and walks the operator through a password reset. Here is how to stop it.
-

A Field Guide to Secure Defaults in 2026
Most breaches in 2026 exploit a default that was wrong at install. The defender who fixes the defaults fixes the breach. Here is the field guide.
-

The Postman Problem and Why Your API Will Get Breached
Every API gets breached the same way. The attacker does not break the API. The API breaks itself, and the developer who built it learns about it from the breach disclosure.
-

Voice Cloning and the Death of Voice Verification
Voice verification sat as the security control the bank, the call center, the enterprise helpdesk relied on for years. The five second voice sample, the my voice is my password pitch, the security control that worked until the voice cloning tools became good enough to defeat it.
-

Why Your MFA Push Notifications Are a Security Hole
The MFA push notification in 2026 sits as the security control the typical enterprise has deployed to replace the password, with the push notification promising the security the password cannot provide. The 2026 reality amounts to the reality where the push notification has become the attack vector the attacker uses, with the MFA fatigue attack,…
-

Your CI/CD Pipeline Is Your Weakest Link
The CI/CD pipeline is the place where the code, the credentials, the secrets, the production access, and the third party integrations all meet, and the place where the security is the thinnest. The CI/CD pipeline is the supply chain, and the supply chain is the attack surface.
-

The Phishing Test Everyone Failed
A simulated phishing email sent to every employee at a mid sized company, the email was a fake package delivery notification, the link went to a fake login page. The click rate was 17 percent. The interesting part is who clicked.
-

Passwordless Is a Five Year Project, Not a Five Month Project
The companies that are treating passwordless like a five month project are the ones whose roadmaps have slipped twice and will slip a third time. The reason it is a five year project is that passwordless is a migration you manage.