Key takeaways A VPN does not make you invisible. It moves who is able to watch your browsing from your internet provider to a VPN company. The classic reason to buy one, protecting yourself on cafe Wi-Fi, has largely been solved by your browser. Almost all web traffic is now encrypted by default. Google is […]
Read MoreKey takeaways SPF and DKIM each validate a domain, but neither looks at the address your recipient actually sees. DMARC exists to connect them to that address, and that connection is called alignment. The DMARC specification was rewritten in May 2026. RFC 9989 replaces RFC 7489, and DMARC is now an IETF Standards Track protocol […]
Read MoreKey takeaways An active phishing campaign is taking over Microsoft 365 accounts by relaying the genuine sign-in page, so multi-factor authentication is completed correctly and the resulting session is stolen anyway. Hundreds of organisations were targeted by email in July across healthcare, education, manufacturing, government and professional services in the United States, Canada and Europe. […]
Read MoreKey takeaways The research released around Black Hat USA 2026 agrees on one thing: AI has compressed attacker timelines, but the way intruders get in has not changed. Phishing was the initial access method in more than half of Cisco Talos incident response engagements last quarter, and authentication abuse appeared in 65 percent of them. […]
Read MoreAttackers have been taking administrative control of the Wi-Fi gateways that hotels and conference centres use to run their guest networks, then quietly rewriting DNS so that travelling employees who try to reach Microsoft 365 land on a page the attacker controls instead. The activity was documented by ReliaQuest Threat Research and has been running […]
Read MoreKey takeaways MFA is the single highest-value security control most businesses can deploy, and it is usually low-cost or free. Microsoft reports it blocks more than 99% of automated account-compromise attacks, the kind that make up the vast majority of what hits your business daily. Not all MFA is equal. SMS codes are the weakest […]
Read MoreKey takeaways: HackOnChat is a global scam, uncovered by security firm CTM360, that hijacks WhatsApp accounts using fake login pages. It works two ways: hijacking your WhatsApp Web session, or tricking you into handing over a verification code. The scam spreads through trust. Once an account is taken over, it messages that person’s contacts asking […]
Read MoreKey takeaways: Most phishing emails can be spotted in under a minute with a few quick checks. The strongest signals are the real sender address, hidden link destinations, and pressure to act fast. Hover over links to see where they really go, and never open unexpected attachments. Polished writing no longer proves an email is […]
Read MoreKey takeaways: Every October, Cybersecurity Awareness Month is a reminder to check your online habits and tighten them. You are not too small to be a target. Everyday users and small businesses are hit just as often as large ones. Four habits cover most of the risk: strong unique passwords, multi-factor authentication, phishing awareness, and […]
Read MoreKey takeaways: Cybersecurity isn’t only for IT teams. If you use email, online banking, or social media, you are already part of it. Most online harm starts with an ordinary, avoidable mistake, like a reused password or a convincing scam message. You are not too small to be a target. Most attacks are automated and […]
Read More