Categories
Every article on the site, grouped by category.
Careers
2 articles Date
How to Become a Digital Forensic Investigator
By Charles Joseph · Updated
Someone has to read the evidence hidden on a seized laptop, and courts need it done right. What the job involves, the skills it takes and how people get there.
Read More
5 Reasons Why Cybersecurity Is a Good Career Choice
By Charles Joseph · Updated
Cybercrime is in every news feed, and the people hired to fight it are in short supply. Five reasons that shortage could be your opportunity.
Read More
Cybersecurity Blog
114 articles Date
Expansion Bus Types, Speeds, and Their Implications for Cybersecurity
By Charles Joseph · Updated
From ISA cards to PCIe and Thunderbolt, every bus that connects a device to your motherboard is also a door. A tour of the generations, the speeds, and the attacks they invite.
Read More
What EDR Platforms Catch: A Quick Breakdown
By Charles Joseph · Updated
Endpoint detection tools are the watchdogs on your devices. Fifty-one things they're trained to sniff out, from ransomware to the subtle stuff.
Read More
What Is the Purpose of an IDS?
By Charles Joseph · Updated
Think of it as a guard who watches the traffic and sounds the alarm. What an intrusion detection system actually does, where it fits, and where it falls short.
Read More
11 Essential Red Team Tools for Cybersecurity Professionals
By Charles Joseph · Updated
Cobalt Strike, Metasploit, Sliver and the rest of the kit professionals use to attack their own employers on purpose. Eleven tools, what each does, and where to get them.
Read More
The Second Disruption of ALPHV/BlackCat Operations
By Nataly Vovk · Updated
An affiliate says the bosses pocketed a $22 million ransom from Change Healthcare. Days later the whole operation went dark again. What happened inside ALPHV.
Read More
The Emerging Threat of a Unified ALPHV-LockBit Ransomware Force
By Nataly Vovk · Updated
The FBI's December raid left ALPHV wounded and looking for options. LockBit is openly recruiting. What a merger of two ransomware giants could look like.
Read More
APT29’s Cyber Espionage Evolution: Adapting to Cloud Security Challenges
By Nataly Vovk · Updated
Russia's SVR hackers have moved on from the office network to the cloud. CISA's advisory spells out the new playbook, and the parts you can still defend against.
Read More
13 Ways to Avoid Getting Hacked
By Charles Joseph · Updated
Unless you plan to unplug for good, the question isn't whether someone will try. Thirteen habits that make you a much harder target.
Read More
11 Signs Your Computer May Be Infected With Malware
By Charles Joseph · Updated
The fan runs hot, the browser has a new toolbar, and something keeps crashing. Eleven symptoms that mean it's time to look closer.
Read More
14 Ways to Secure Linux
By Charles Joseph · Updated
Linux has a reputation for being safe out of the box. It earns that reputation only after you've done a few things to it. Fourteen of them, in order.
Read More
30 Best Movies About Hackers and Cybersecurity
By Charles Joseph · Updated
From a 1983 teenager dialing into a military computer to the heists of the 2000s, Hollywood has been hacking for decades. Thirty films worth your weekend, accuracy optional.
Read More
45 Commands: Linux/Bash to PowerShell (With Examples)
By Charles Joseph · Updated
You know the Bash command by heart. Now you're on Windows. Forty-five translations into PowerShell, with examples you can paste.
Read More
Ransomware Rebellion: A Fight for Digital Freedom
By Charles Joseph · Updated
Something sinister is loose on the computers of St. Maria's University, and Zack Harper has to stop it. Ransomware best practices, delivered as a story.
Read More
Tencent: Is this Chinese Company a Privacy Threat?
By Charles Joseph · Updated
WeChat, blockbuster games, cloud and payments: Tencent touches more lives than almost any company on earth. Its five businesses, and the questions that follow them.
Read More
Major Brands’ Subdomains Compromised to Send Millions of Malicious Emails
By Nataly Vovk · Updated
Thousands of forgotten subdomains belonging to household names were quietly hijacked. The SubdoMailing scheme shows how a brand's own trust gets turned against its customers.
Read More
Top Cyber Defense Strategies for U.S. Water Systems
By Nataly Vovk · Updated
CISA, the FBI and the EPA wrote a joint playbook for the utilities that keep the taps running. The actions they want water systems to take first.
Read More
Knight Ransomware Source Code Available for Sale
By Nataly Vovk · Updated
A ransomware crew is selling its newest version to a single buyer, and only one. What the Knight code does and why exclusivity is the selling point.
Read More
Medusa’s Strategic Evolution: Blending Extortion and Stealth in Ransomware Operations
By Nataly Vovk · Updated
Medusa was a quiet operation until it opened a leak site in early 2023. Since then it has been anything but. How the group picks its targets and turns the screws.
Read More
Operation Cronos: International Force Disrupts LockBit Ransomware Network
By Nataly Vovk · Updated
One of the most active ransomware services around just had its own infrastructure seized. What Operation Cronos took, and how LockBit's affiliate model works.
Read More
U.S. Offers a Multi-Million Dollar Reward for Information about ALPHV/Blackcat
By Nataly Vovk · Updated
After more than a thousand victims and one FBI raid, the State Department has put a price on ALPHV's leaders. Up to $10 million, if you know where to look.
Read More
Microsoft Warns about Russian State-Sponsored Espionage Attacks
By Nataly Vovk · Updated
Microsoft confirmed the SVR's hackers were inside its systems, then started warning other victims. What Midnight Blizzard did once it got in, and the techniques to watch for.
Read More
Threat Actors Posing as Ethical Hackers
By Nataly Vovk · Updated
Victims of Royal and Akira ransomware are getting a second visit from strangers offering to help. Arctic Wolf's investigators found out who those helpers really are.
Read More
19 Cybercriminals Face Justice in Global Law Enforcement Operation
By Nataly Vovk · Updated
The xDedic marketplace sold logins to hacked servers around the world. Charges against nineteen people show how far the cooperation behind the takedown stretched.
Read More
Sea Turtle Targets Dutch IT and Telecom Sectors
By Charles Joseph · Updated
A Turkish-linked espionage group has been working its way through Dutch ISPs, telecoms and Kurdish websites. What Sea Turtle is after and how it gets in.
Read More
The Admin Behind Cybercriminal BreachForums Was Re-Arrested
By Nataly Vovk · Updated
Pompompurin walked out on pretrial release with a few simple conditions. A computer and a VPN later, the marshals were back at the door.
Read More
Tech Entrepreneur Falls Victim to Cryptocurrency Scam, Loses $125K
By Charles Joseph · Updated
He co-founded a crypto wallet company, and still an airdrop article led him to a near-perfect fake site. How the phish worked on a professional.
Read More
HealthEC Data Breach Impacted 4.5 Million Patients
By Nataly Vovk · Updated
Names, Social Security numbers, diagnoses and insurance details, all in one ten-day window. What HealthEC's breach exposed and who it reached.
Read More
Fighting Fraudulent AI: FTC Announces $25,000 Prize for Voice Cloning Detection
By Nataly Vovk · Updated
A ten-day contest and a $25,000 prize for anyone who can tell a cloned voice from the real thing. Why the FTC thinks the problem can't wait.
Read More
Dropbox Users Spooked by AI Feature Sharing Data with OpenAI
By Charles Joseph · Updated
A new AI search feature arrived with a setting already switched on. Users who noticed were not thrilled about where their files might be going.
Read More
Australian Court Recordings Database Hacked
By Charles Joseph · Updated
Hearings in Victoria's courts are recorded and transcribed on one network, and someone got in. Seven weeks of recordings may now be in the wrong hands.
Read More
Trump’s Former Attorney, Michael Cohen, Used Google Bard in Attempt to Shorten Probation
By Charles Joseph · Updated
A motion to end his probation early cited cases nobody could find. The source turned out to be a chatbot.
Read More
Massive Cyberattacks Expose Millions in Iran: Suspicions of State Involvement Arise
By Charles Joseph · Updated
Insurance records and food delivery accounts for a large slice of Iran's population spilled out within weeks. The scale alone has investigators asking who was really behind it.
Read More
Third-Party Music Converter Used by Spotify, Audible, and Apple Music Exposed User Data
By Charles Joseph · Updated
A Hong Kong tool for ripping music from streaming services left its users' private data open to the internet. What leaked, and who was affected.
Read More
Terrifying Tale of Cyber-Kidnapping: Chinese Exchange Student Found in Utah
By Charles Joseph · Updated
A ransom photo reached his parents in China while he was alone in the Utah mountains. The strange crime called cyber-kidnapping, and how this one ended.
Read More
Phishing Attacks On Cryptocurrency Wallets Escalate
By Charles Joseph · Updated
Across Ethereum, Polygon, Avalanche and more than a dozen other chains, wallets are being drained with tailored lures. The group selling the kit is called Angel Drainer.
Read More
The FBI’s 2023 Cybercrime Offensive: A Year in Review
By Nataly Vovk · Updated
Ransomware gangs, dark web markets, a spy malware network and a botnet all went down in a single year. How the Bureau's biggest takedowns of 2023 unfolded, one by one.
Read More
When Winning Feels Like Losing: Ohio Lottery’s Cyber Battle
By Charles Joseph · Updated
A Christmas Eve attack left Ohio's lottery unable to pay out its bigger prizes. What was hit, and what winners were left waiting on.
Read More
Russian Military Deploys MASEPIE Malware Against Ukraine
By Charles Joseph · Updated
Ukraine's CERT has flagged a new tool in APT28's hands. What MASEPIE does once it lands, and why Fancy Bear keeps coming back.
Read More
Ernie Bot Surpasses 100 Million User Milestone
By Charles Joseph · Updated
Baidu opened its chatbot to the public in August, and the numbers moved fast. What the milestone says about China's crowded AI race.
Read More
Unsettled Query: Google’s Data Collection Practices Questioned in $5 Billion Consumer Privacy Lawsuit
By Charles Joseph · Updated
Millions of people thought incognito meant private. A $5 billion lawsuit argued otherwise, and Google has chosen to settle rather than face a jury.
Read More
Ransomware Attack in Hangzhou Leads to Arrests and Raises AI Concerns in China
By Charles Joseph · Updated
A company in Hangzhou was locked out of its systems and asked for $20,000 in Tether. The arrests came quickly. The part about AI is what has China worried.
Read More
Yakult Australia Falls Victim to Major Cyberattack
By Charles Joseph · Updated
The probiotic drink maker lost 95 gigabytes of internal files to the dark web. Who claimed the attack, what was in the leak and how the company responded.
Read More
What Is Ahrefs? Can It Be Used for Cybersecurity?
By Charles Joseph · Updated
Marketers know it for backlinks and keyword research. Whether the same toolbox earns a place in a security kit is a fairer question than it sounds.
Read More
APT1: Cyber Espionage’s Most Wanted
By Charles Joseph · Updated
The Comment Crew spent years inside American companies before anyone put a name to it. Who they are, how they work, and the report that blew their cover.
Read More
1.3 Million Victims: The Devastating Impact of ALPHV’s Attack on FNF and LoanCare
By Charles Joseph · Updated
The gang behind the MGM and Caesars attacks turned to a mortgage giant next. How investigators tied ALPHV to the breach, and what LoanCare customers lost.
Read More
LockBit Suspected in Devastating Ransomware Strike on Three German Hospitals
By Charles Joseph · Updated
On Christmas Eve, three hospitals in one German network lost their systems at once. The signs point to a familiar gang.
Read More
China’s New Step in AI: Balancing Innovation and Regulation
By Charles Joseph · Updated
Beijing wants a booming AI industry and tight control over what public chatbots say. The new rules show how it plans to have both.
Read More
5 Reasons Why Data Backups Are Critical
By Charles Joseph · Updated
Backups are the chore every IT person nags you about, right up until the day you need one. Five reasons they're worth the hassle before disaster strikes.
Read More
Hackers Offer Unauthorized Access to Chinese Surveillance Systems
By Charles Joseph · Updated
Tens of thousands of Hikvision cameras are still running with a flaw patched years ago. Now access to them is being sold, and the cameras are everywhere.
Read More
Motorola’s Ex-Employee Caught in Explosive Cyberattack and Passport Fraud
By Charles Joseph · Updated
A former technician hit his old employer's network, then tried to leave the country on papers that weren't his. How a cyberattack turned into a passport case.
Read More
How a Miami Gang Leader Pulled Off a $4 Million Crypto Heist
By Charles Joseph · Updated
A Miami gang leader, U.S. banks, a crypto exchange and $4 million that vanished. How the scheme worked, and how it ended in a New York courtroom.
Read More
5 Controversies About Kaspersky Lab
By Charles Joseph · Updated
One of the world's biggest antivirus makers is also one of its most argued over. Five episodes, from a U.S. ban to an Israeli intelligence discovery, that explain why.
Read More
What Is Wireshark?
By Charles Joseph · Updated
Every packet on the network has a story, and Wireshark reads them all. What the open-source sniffer does, who relies on it, and how it earns its keep.
Read More
How to Secure WordPress (11 Suggestions)
By Charles Joseph · Updated
WordPress runs more than a third of the web, which makes it a favorite target. Eleven fixes, from the obvious to the ones most site owners skip.
Read More
13 Tips to Protect Your PII
By Charles Joseph · Updated
Your name, your birthday, your Social Security number: identity thieves need surprisingly little. Thirteen ways to give them less.
Read More
How to Secure Wi-Fi (12 Suggestions)
By Charles Joseph · Updated
Your router shipped with a default password and a few settings you've never touched. Twelve changes that turn it from an easy target into a locked door.
Read More
14 Essential Reasons to Use a VPN
By Charles Joseph · Updated
Privacy is the obvious reason, but it's far from the only one. Fourteen things a VPN does for you, from public Wi-Fi to the shows your region can't see.
Read More
5 Reasons Why Hackers Use Malware
By Charles Joseph · Updated
Money, secrets, sabotage or an army of hijacked machines. Malware is a means to an end, and five ends explain most of what you'll ever see.
Read More
5 Ways to Reduce the Risk of Phishing
By Charles Joseph · Updated
The email looks right, the logo is perfect, and the link is one click away. The habits that catch a phish before it catches you.
Read More
Why Regularly Update Software and Operating Systems?
By Charles Joseph · Updated
Those update reminders are easy to swat away, especially when a restart is the last thing you need. Six reasons the savvy move is to let them through.
Read More
F-Secure: An In-Depth Look at the Finnish Cybersecurity Powerhouse
By Charles Joseph · Updated
It started in Helsinki in 1988, before most people had heard of the internet. Seven facts about the company once known as Data Fellows, and what it sells today.
Read More
What Is the Hidden Wiki and How to Find It
By Charles Joseph · Updated
The dark web has a front page, of sorts. Where the Hidden Wiki came from, who uses it, and how to reach it through Tor.
Read More
AlphaBay: Inside the Infamous Dark Web Marketplace
By Charles Joseph · Updated
Hundreds of thousands of users, millions in yearly revenue, and a founder hiding behind the handle Alpha02. The rise of the Silk Road's successor, and the hunt that ended it.
Read More
Silk Road: Dark Web Marketplace
By Charles Joseph · Updated
An Amazon for the things you can't buy on Amazon, run by a man calling himself Dread Pirate Roberts. How Silk Road worked, what it sold, and how it ended.
Read More
7 Alarming Data Privacy Statistics
By Charles Joseph · Updated
How long does a breach go unnoticed, and how often does a hacker strike? Seven numbers that reframe the way you think about your own data.
Read More
Navigating the Impact of EO 14028
By Charles Joseph · Updated
Signed in the wake of Colonial Pipeline, Executive Order 14028 rewrote the federal cybersecurity rulebook. What it demands, and why it reaches well beyond Washington.
Read More
6 Reasons to Disable IPv6
By Charles Joseph · Updated
IPv6 is the future of addressing, which doesn't mean you need it today. Six situations where turning it off makes sense, and the trade-offs that come with that.
Read More
Cyber Kill Chain: How to Mitigate Advanced Threats
By Charles Joseph · Updated
Lockheed Martin broke an attack into seven stages so defenders could break it back. What each step looks like, and where you can interrupt it.
Read More
Linux: Essential Commands for IR Triage
By Charles Joseph · Updated
You've just been hacked, your boss wants answers, and there's no plan. The Linux commands that tell you what happened while you still can.
Read More
6 Types of Cyber Threat Actors
By Charles Joseph · Updated
Six kinds of attacker, six sets of motives and fingerprints. Knowing which one you're facing changes everything about the defense.
Read More
BIOS vs UEFI: Which Is More Secure?
By Charles Joseph · Updated
Both wake your computer up, but they go about it very differently. What each firmware does before the operating system ever loads, and where security comes in.
Read More
What Is Shodan?
By Charles Joseph · Updated
Google indexes web pages. Shodan indexes the webcams, routers and servers behind them. Where it came from and six ways people use it.
Read More
Censys: Uncovering the Global Attack Surface for Enhanced Cybersecurity
By Charles Joseph · Updated
A team of University of Michigan researchers set out to scan the entire internet. Nine things their company now does with that view, and why defenders pay for it.
Read More
What Is a Non-Disclosure Agreement? (6 Key Elements)
By Charles Joseph · Updated
Before anyone shares a secret in business, they sign one of these. The six parts every NDA needs, and what happens when one is missing.
Read More
What Is a Remote Browser and Why Use One?
By Charles Joseph · Updated
The web page loads on a server somewhere else, and only the picture reaches you. Why that odd arrangement is catching on for security, privacy and old software.
Read More
How to Create a Sock Puppet for OSINT Investigations
By Charles Joseph · Updated
Investigators, journalists and pentesters all need an online identity that can't be traced back to them. Seven steps to building one properly.
Read More
How to Create a Strong and Secure Password
By Charles Joseph · Updated
Somebody out there is still using 123456. A few bad examples, a few good ones, and the habits that keep your accounts your own.
Read More
What to Do if You’ve Been Hacked or Your Info Has Been Compromised
By Charles Joseph · Updated
The first hour after a breach matters more than the next month. What to lock down, who to call and how to keep a bad day from getting worse.
Read More
All 4 PCI Compliance Levels Explained
By Charles Joseph · Updated
Every business that touches a card number falls into one of four PCI DSS levels. Which one you are decides how much work the audit will be.
Read More
How Does a Cyber Threat Group Get Its Name?
By Charles Joseph · Updated
Fancy Bear, Lazarus, APT1. The names sound like comic books, but each follows a method. Five ways the security world christens its adversaries.
Read More
How Does Diffie-Hellman Work?
By Charles Joseph · Updated
Alice and Bob want a secret, and everyone is listening. The trick that lets two strangers agree on a number nobody else can work out, without the math headache.
Read More
What Is Salting in Password Security and How Does It Work?
By Charles Joseph · Updated
Two people pick the same password, yet their hashes look nothing alike. The pinch of randomness that makes stolen password databases far less useful.
Read More
Is the SSL/TLS Protocol Enough for Network Security?
By Charles Joseph · Updated
The padlock in the address bar does one job very well. Whether that job covers everything you're worried about is a different question.
Read More
What’s the Difference Between Stored and Reflected XSS?
By Charles Joseph · Updated
One lives on the server and waits for every visitor. The other needs a victim to take the bait. Two flavors of cross-site scripting, side by side.
Read More
The Cryptic Handshake: Unraveling the Three-Way Dance of the Digital Realm
By Charles Joseph · Updated
A knock at the door, a cryptic reply, and one final confirmation. The TCP handshake, told as the little story it secretly is.
Read More
The Cybersecurity Maverick Who Took on a Hacker Group
By Charles Joseph · Updated
Zack Bartholomew has a company to save and a hacker crew called the Enlightened to outwit. A story that teaches honeypots and incident response without feeling like a lesson.
Read More
Incident Response for 15 Common Attack Types
By Charles Joseph · Updated
Ransomware, phishing, DDoS, insider misuse. Each needs a different first move. One table that lays out the response for fifteen kinds of attack.
Read More
Leading Network Equipment Providers and Their Origins
By Charles Joseph · Updated
The switches and routers behind the modern internet come from a handful of companies with surprisingly scrappy beginnings. Where the big names came from.
Read More
NetFlow vs. Packet Capture: Understanding Differences and Use Cases
By Charles Joseph · Updated
One tells you who talked to whom. The other keeps every word. When a summary of your traffic is enough, and when you need the full recording.
Read More
3 Ways to Restrict a Docker Container’s Internet Access
By Charles Joseph · Updated
Your containers can reach the whole internet by default, which is rarely what you want. Three ways to cut the cord, from an isolated network to dropped capabilities.
Read More
Does Email Spoofing Mean You’ve Been Hacked?
By Charles Joseph · Updated
An email just went out with your name on it, and you never wrote it. What spoofing really takes, and what it means for the account you're worried about.
Read More
How to Limit Docker Container Resources (4 Methods)
By Charles Joseph · Updated
One runaway container can starve everything else on the host. Four flags that keep CPU and memory on a leash, with the commands to copy.
Read More
20 Cybersecurity Myths and Misconceptions
By Charles Joseph · Updated
The firewall is fine, the vendor is trustworthy, and nobody here would click that link. Twenty comfortable beliefs that deserve a second look.
Read More
10 Cybersecurity Vulnerabilities and How They’re Mitigated
By Charles Joseph · Updated
Weak passwords, stale software, a misconfigured server. The ten weaknesses attackers find first, each paired with the fix that closes it.
Read More
How to Identify and Report a Cybercrime
By Charles Joseph · Updated
You think you've been scammed, phished or broken into. What to preserve, who to call first, and where the report actually goes.
Read More
Genesis Market Takedown (aka Operation Cookie Monster)
By Charles Joseph · Updated
Seventeen countries, 119 arrests and a marketplace for stolen logins pulled offline in one sweep. One loose end still lingers on the dark web.
Read More
Should Governments Have Access to Encryption Backdoors?
By Charles Joseph · Updated
A key that only the good guys can use sounds reasonable until you ask who keeps it. The case for backdoors, the case against, and why the debate won't settle.
Read More
JavaScript Essentials: A Comprehensive Guide to Core Concepts
By Charles Joseph · Updated
Single-threaded, yet it juggles a thousand things at once. The event loop, the call stack and the ideas that make JavaScript tick, explained from the ground up.
Read More
TLS vs. HTTPS
By Charles Joseph · Updated
Everyone has seen the S in HTTPS. Fewer people know where TLS ends and HTTPS begins. How a plain web request becomes a protected one, step by step.
Read More
How to Prevent Cyber War between Nations
By Charles Joseph · Updated
Nations now fight with code as readily as with bombs. The same tools that kept old wars from starting might work here too, if anyone is willing to use them.
Read More
Russian Hackers Take to the Skies: KillNet Hacks Eurocontrol
By Charles Joseph · Updated
Europe's air traffic coordinator went down under a pro-Russian attack, and flights paid the price. How the breach unfolded and what could stop the next one.
Read More
American Bar Association: Hackers Crack the Bar (and 1.5 Million Accounts)
By Charles Joseph · Updated
Lawyers and law students woke up to a breach notice from their own professional body. What the attackers reached, and what members were told to do next.
Read More
Google’s AI Powerhouses Unite – What Does This Mean for the Future of AI?
By Charles Joseph · Updated
DeepMind and Google Brain spent a decade as rivals under one roof. Now they're one lab, and the reasons behind the merger say a lot about where AI is heading.
Read More
Are Your IoT Devices Spying on You?
By Charles Joseph · Updated
Smart speakers, cameras and thermostats work quietly in the background, collecting as they go. Five sides of IoT security decide whether that's a convenience or a leak.
Read More
Guide to Chatbots: ChatGPT, Google Bard, and Microsoft Bing
By Charles Joseph · Updated
Three chatbots, three very different ideas of what an assistant should be. A side-by-side look at what each does well before you pick one for your daily work.
Read More
What Is the Pi Network? (Cryptocurrency)
By Charles Joseph · Updated
A coin you mine by tapping your phone, built by Stanford professors. Revolution, fad or something murkier? The history and the criticism, laid out.
Read More
Docker Containers: Boosting Your Cybersecurity Strategy
By Charles Joseph · Updated
Containers changed how software ships. They can also change how safely it runs, if you know which features to lean on and which habits to drop.
Read More
Are VPNs Legal?
By Charles Joseph · Updated
Routing your traffic through a VPN is one of the savviest privacy moves you can make. Before you do, it pays to know where the law draws its lines.
Read More
How to Unblock Instagram at School (2023)
By Charles Joseph · Updated
The school network says no. Your phone, and a couple of other tricks, might say otherwise. Two dead-simple methods, and why schools block it in the first place.
Read More
Big Brother in Your Pocket: The New Era of Digital Surveillance
By Charles Joseph · Updated
From Paris to Berlin to Washington, police are gaining new ways to reach into your phone. The tools they use, the laws that allow it, and how to push back.
Read More
Cybercrime in France: The Legislative Landscape
By Charles Joseph · Updated
Known for wine and landmarks, France has also built one of Europe's toughest legal frameworks against cybercrime. The laws, the agency behind them, and where they go next.
Read More
AWS Instance Metadata Service (IMDS): Is It Secure?
By Charles Joseph · Updated
Every EC2 instance answers questions about itself at one internal address, to anyone with a terminal and curl. What it reveals, and how to keep that from becoming a problem.
Read More
How Attackers Eavesdropped on a Popular Messaging Platform for Months
By Charles Joseph · Updated
Somebody sat between jabber.ru and its users for months without anyone noticing. How the interception worked, and how it finally came to light.
Read More
Roaming or Being Watched? How Cellphone Roaming Exposes Your Every Move
By Charles Joseph · Updated
Cross a border and your phone quietly introduces itself to a new network. A Citizen Lab report explains who else can listen in on that conversation.
Read More
Terms
736 articles Date
What Is EDR?
By Charles Joseph · Updated
Antivirus misses things. EDR watches every endpoint, catches the ransomware and lets you respond. What it does, when you need it, and what it costs.
Read More
Mutual TLS: Strengthening Network Security with Two-Way Authentication
By Charles Joseph · Updated
Standard TLS verifies the server. Mutual TLS makes the client prove itself too. How mTLS works, where it came from, and when it's worth the effort.
Read More
What Is pfSense?
By Charles Joseph · Updated
A free, open-source firewall and router built on FreeBSD. Where pfSense came from, and four reasons to use it.
Read More
What is Grayware and How Can It Affect You?
By Charles Joseph · Updated
Not quite malware, not quite harmless. What grayware is, where spyware and adware fit, and the numbers behind the gray zone.
Read More
What Is the QAZ Network Worm?
By Charles Joseph · Updated
A worm that spreads fast and steals account details on Windows. How QAZ works, with examples from email to gaming.
Read More
Non-Printable Character: What Is Its Significance in Cybersecurity?
By Charles Joseph · Updated
Tabs, line breaks and carriage returns are invisible, but not harmless. What non-printable characters are, and why they matter in security.
Read More
Symbolic Links: What Are the Security Risks of Symbolic Links?
By Charles Joseph · Updated
A shortcut that points to the real file somewhere else. How symlinks organize files and save space, and the security risks they carry.
Read More
Steganalysis: How to Conduct Effective Steganalysis?
By Charles Joseph · Updated
Finding the message hidden inside an image, an audio file or a text. How steganalysis works, and how to do it well.
Read More
Session Key: Why Is a Session Key Necessary?
By Charles Joseph · Updated
A fresh key for every connection, thrown away when you log out. Why banking, social platforms and email all rely on session keys.
Read More
Synchronization: How Important Is Time Synchronization in Security?
By Charles Joseph · Updated
Clocks that drift, code that conflicts, threads that collide. Why synchronization matters in networks, development and security.
Read More
Keylogger: How Safe Is Your Keyboard?
By Charles Joseph · Updated
Every keystroke recorded, from passwords to card numbers. How keyloggers are used by parents, employers and criminals, and how dangerous they are.
Read More
Open Shortest Path First (OSPF): How Does It Benefit Routing?
By Charles Joseph · Updated
Company branches, ISPs and smart homes all need the best route between points. How OSPF finds it, and why it's popular.
Read More
How Does Stimulus Affect System Behavior?
By Charles Joseph · Updated
A click, a like, a button press. What a stimulus is, and how systems respond to it.
Read More
Secure Shell (SSH): Why Use SSH for Remote Login?
By Charles Joseph · Updated
Log in to a remote machine, run commands and move files, all encrypted. How SSH works, with examples.
Read More
TCP Fingerprinting: How Reliable Is It?
By Charles Joseph · Updated
How a device answers packets reveals its operating system. How TCP fingerprinting works, and how reliable it is.
Read More
The Ransomware Menace: Understanding and Mitigating Risks
By Charles Joseph · Updated
The go-to weapon for cybercriminals, fueled by cryptocurrency. How ransomware spreads, encrypts and demands payment, and how to mitigate the risk.
Read More
Domain Name Stats, Insights, and Trends
By Charles Joseph · Updated
There are hundreds of millions of domain names, and the number keeps changing. What a domain name is, plus the latest numbers from the industry.
Read More
User Contingency Plan: Why Is It Essential?
By Charles Joseph · Updated
Power outages, hardware failures, network attacks. What a user contingency plan covers, and why it's essential.
Read More
Trust: How Important Is Trust in Cybersecurity?
By Charles Joseph · Updated
Banking, e-commerce and digital communication all rest on it. What trust means in cybersecurity, and why it matters.
Read More
Switch: What Makes a Network Switch Secure?
By Charles Joseph · Updated
Smarter than a hub, sending data only where it belongs. What a switch does at home, in small business and in schools, and what makes one secure.
Read More
Straight-Through Cable
By Charles Joseph · Updated
Computer to router, computer to switch. What a straight-through cable is, and when to use one.
Read More
Reverse Lookup: What Can It Reveal?
By Charles Joseph · Updated
Start with an IP address, end with a domain. How reverse lookups analyze traffic, detect email fraud and diagnose network issues.
Read More
Cross-Domain Solutions: The Layman’s Guide
By Charles Joseph · Updated
Two networks with different security rules need to talk. A cross-domain solution is the trusted bridge between them. What it is, why it matters and how it differs from a firewall.
Read More
Token-Based Devices: How Secure Are They?
By Charles Joseph · Updated
SecurID fobs, Google Authenticator, YubiKey. How token devices generate codes, and how secure they are.
Read More
TCP Half Open Scan
By Charles Joseph · Updated
Start the handshake, then reset before it finishes. How half open scans find open ports without completing a connection.
Read More
Store-and-Forward: How Does It Work?
By Charles Joseph · Updated
Email, fax and voicemail all wait at a station before moving on. How store-and-forward communication works.
Read More
Pretty Good Privacy (PGP): How Does It Protect Communications?
By Charles Joseph · Updated
Sign, encrypt and decrypt email, files and whole disks. How PGP protects communications, and why it's still around.
Read More
Vishing (Voice or VoIP Phishing): How to Recognize & Prevent Vishing?
By Charles Joseph · Updated
A bank call, a tech support call, a prize call. How vishing works, and how to recognize and prevent it.
Read More
System Security Officer (SSO): What Are the Responsibilities of an SSO?
By Charles Joseph · Updated
Routine checks, staff training and breach management. What a system security officer does, and why the role matters.
Read More
Protocol Stacks (OSI): How Do They Enable Networking?
By Charles Joseph · Updated
Email, browsing and file transfers pass through seven layers. How the OSI protocol stack enables networking, with examples.
Read More
Traceroute: How to Use It for Network Diagnostics?
By Charles Joseph · Updated
Every hop between you and the destination, listed. How traceroute diagnoses website issues, network problems and gaming lag.
Read More
Voice Firewall: What Is It and How Does It Work?
By Charles Joseph · Updated
Monitor and control calls to stop eavesdropping, fraud and tampering. What a voice firewall is, and how it works.
Read More
Unprotected Share: What Are the Risks?
By Charles Joseph · Updated
A shared folder with no restrictions at all. The risks in offices, homes and agencies.
Read More
Hypertext Markup Language (HTML): How Secure Is It?
By Charles Joseph · Updated
Tags, structure and links: the backbone of every web page. How HTML works, and where its security limits lie.
Read More
VirusTotal: The Cybersecurity Practitioner’s Multi-Engine Shield
By Charles Joseph · Updated
Submit a file or URL and dozens of engines scan it at once. How VirusTotal works, its strengths and limits, and when to use it.
Read More
Transport Layer Security (TLS): How Reliable Is TLS Encryption?
By Charles Joseph · Updated
Shopping, email and banking, protected in transit. How TLS works, and how reliable the encryption is.
Read More
Virtual Private Network (VPN): How Secure Is a VPN?
By Charles Joseph · Updated
Remote work, streaming and safe shopping from a café or an airport. How a VPN works, and how secure it is.
Read More
User Datagram Protocol (UDP): When to Use UDP Over TCP?
By Charles Joseph · Updated
Fast delivery, no confirmation. When UDP beats TCP for gaming, streaming and internet calls.
Read More
Triple-Wrapped: What Is Triple-Wrapped Security?
By Charles Joseph · Updated
Three layers of encryption around one piece of data. How triple wrapping protects email, financial transfers and confidential files.
Read More
Transmission Control Protocol (TCP): Why Is TCP Essential for Internet?
By Charles Joseph · Updated
Email, browsing and file transfers depend on reliable delivery. How TCP works, and why it's essential.
Read More
What Is tcpdump?
By Charles Joseph · Updated
Capture network traffic from the command line. How tcpdump monitors interfaces, tracks IP addresses and inspects HTTP.
Read More
Time to Live: What Is the Purpose of TTL in Networking?
By Charles Joseph · Updated
Every packet has an expiry. How TTL works in email, browsing and gaming, and why it matters.
Read More
Tiny Fragment Attack: How to Counter Tiny Fragment Attacks?
By Charles Joseph · Updated
Harmful data broken into pieces too small to notice. How tiny fragment attacks slip past firewalls, and how to counter them.
Read More
What Is Token-Based Access Control?
By Charles Joseph · Updated
Log in once, carry a token. How token-based access works for social media, banking and cloud services.
Read More
What Is Token Ring?
By Charles Joseph · Updated
Pass the token, take your turn. How token ring networks worked in offices, school labs and conferences.
Read More
Strong Star Property: What Is the Strong Star Property in Security?
By Charles Joseph · Updated
Lower-level data can't be written into a higher-level space. How the strong star property protects banks, hospitals and schools.
Read More
System-Specific Policy: What Is a System-Specific Policy?
By Charles Joseph · Updated
A CRM, a grading system, patient records. What a system-specific policy covers, with examples.
Read More
T3: What Are the Benefits of a T3 Line?
By Charles Joseph · Updated
45 megabits per second for newsrooms, online shops and universities. What a T3 line offers, and its benefits.
Read More
Tamper: How to Prevent Tampering of Data?
By Charles Joseph · Updated
Web code, email content, software binaries, all altered without permission. How tampering works, and how to prevent it.
Read More
TCP Full Open Scan: How Does a TCP Full Open Scan Work?
By Charles Joseph · Updated
Send a SYN, wait for the answer, and learn which ports are open. How full open scans work for assessments, consultants and pre-deployment tests.
Read More
Split Key: What Is the Advantage of Split Key Encryption?
By Charles Joseph · Updated
Divide the key, and no single person can unlock the data. How split keys protect banking, email and storage.
Read More
Split Horizon: How Does Split Horizon Prevent Loops?
By Charles Joseph · Updated
Never send a route back to where you learned it. How split horizon stops routing loops in RIP, with examples.
Read More
SQL Injection: How to Prevent SQL Injection?
By Charles Joseph · Updated
A login bypassed, a database dumped, a site defaced, all from one unchecked input field. How SQL injection works, and how to prevent it.
Read More
Stack Mashing: What Is Stack Mashing in Cybersecurity?
By Charles Joseph · Updated
A name field, a message body, a player name, each overflowed on purpose. What stack mashing is, and how it exploits a program's memory.
Read More
Star Property: What Is the Star Property in Security Models?
By Charles Joseph · Updated
No writing down. How the Bell-LaPadula star property keeps secrets from leaking, in corporations, hospitals and government.
Read More
State Machine: How Does State Machine Modeling Enhance Security?
By Charles Joseph · Updated
A vending machine, a traffic light, a computer's sleep mode. How state machines work, and how modeling with them improves security.
Read More
Stateful Inspection: Why Is Stateful Inspection Crucial in Firewalls?
By Charles Joseph · Updated
A firewall that remembers which connections you started. How stateful inspection protects browsing, email and gaming.
Read More
Spoof: How to Protect Against Spoofing Attacks?
By Charles Joseph · Updated
Email, caller ID and IP addresses can all be faked. How spoofing works, and how to protect against it.
Read More
Steganography: What Is the Role of Steganography in Cybersecurity?
By Charles Joseph · Updated
A message hidden in a picture, a song or a video. How steganography works, and its role in security.
Read More
Stealthing: How to Detect Stealth Malware?
By Charles Joseph · Updated
Hidden processes, hidden files, hidden traffic. How stealth techniques keep malware invisible, and how to detect it.
Read More
Static Routing: What Are the Pros and Cons of Static Routing?
By Charles Joseph · Updated
Routes set by hand and left alone. The pros and cons of static routing for small businesses, schools and homes.
Read More
Static Host Tables: How Efficient Are Static Host Tables?
By Charles Joseph · Updated
Hostnames paired with addresses by hand, for when DNS isn't enough. How static host tables work in offices, small businesses and homes.
Read More
Shadow Password Files: Why Use Shadow Password Files?
By Charles Joseph · Updated
Linux keeps the encrypted passwords where ordinary users can't read them. How shadow files work when accounts are created, changed and audited.
Read More
Share: What Are the Risks of Network Shares?
By Charles Joseph · Updated
An email attachment, a Google Doc, a network drive. What sharing means, and the risks that come with every open door.
Read More
Simple Network Management Protocol (SNMP): Why Is SNMP Essential?
By Charles Joseph · Updated
ISPs, big companies and campuses watch their routers and servers through it. What SNMP does, and why networks depend on it.
Read More
Simple Security Property: What Does Simple Security Property Ensure?
By Charles Joseph · Updated
No reading above your level. How the simple security property protects company documents, medical records and audit reports.
Read More
Smartcard: How Safe Is a Smartcard?
By Charles Joseph · Updated
Credit cards, employee IDs and SIM cards all carry a chip that thinks. How smartcards work, and how safe they are.
Read More
Smishing: How to Detect and Prevent Smishing?
By Charles Joseph · Updated
A text about your bank, a gift card win, a shipping alert. How smishing works, and how to detect and prevent it.
Read More
Sniffer: How Dangerous Can a Packet Sniffer Be?
By Charles Joseph · Updated
A tool that reads network traffic, for troubleshooting or for theft. What sniffers do, and how dangerous one can be.
Read More
Socket: What Is a Network Socket?
By Charles Joseph · Updated
An IP address plus a port number is a doorway for data. How sockets work in browsing, email and gaming.
Read More
Socket Pair: What Is a Socket Pair in Networking?
By Charles Joseph · Updated
A client that initiates and a server that listens. How socket pairs enable two-way communication in browsing, email and games.
Read More
Source Port: Why Is Source Port Important in Networking?
By Charles Joseph · Updated
The number that identifies which program sent the data. Why source ports matter for browsing, email and gaming.
Read More
Session Hijacking: How to Prevent Session Hijacking?
By Charles Joseph · Updated
Someone takes over your logged-in session and carries on as you. How hijacking hits email, banking and social media, and how to prevent it.
Read More
Session: What Happens During a Network Session?
By Charles Joseph · Updated
Shopping, email and banking all happen inside a session. What starts one, what ends it, and what gets tracked in between.
Read More
Server: What Makes a Server Secure?
By Charles Joseph · Updated
Web servers, database servers and file servers. What a server does, and what makes one secure.
Read More
Root: What Is the Significance of Root in Cybersecurity?
By Charles Joseph · Updated
The highest level of access on any system. How root works on smartphones, web hosts and home computers, and why hackers want it.
Read More
Routing Information Protocol (RIP): What Are the Limitations of RIP?
By Charles Joseph · Updated
Count the hops and pick the shortest path. How RIP works for home, company and ISP networks, and where it falls short.
Read More
Routing Loop: How to Prevent Routing Loop Problems?
By Charles Joseph · Updated
Packets circling forever between routers. How routing loops happen, with examples, and how to prevent them.
Read More
RPC Scans: Why Are RPC Scans Important?
By Charles Joseph · Updated
Open RPC services are an invitation. How RPC scans find them in enterprise, home and cloud networks, and why regular scanning matters.
Read More
Rule Set Based Access Control (RSBAC): Is RSBAC More Secure than RBAC?
By Charles Joseph · Updated
Pre-defined rules decide who can do what, when and where. How RSBAC works, and whether it's more secure than role-based control.
Read More
S/Key: What Is Its Purpose?
By Charles Joseph · Updated
A password you use once and throw away. How S/Key one-time passwords protect online banking, remote servers and corporate networks.
Read More
Safety: How Critical Is Cyber Safety?
By Charles Joseph · Updated
Complex passwords, updated antivirus, no suspicious links. What cyber safety means, and how critical it is.
Read More
Scavenging: Why Should You Avoid DNS Scavenging?
By Charles Joseph · Updated
A discarded hard drive, an unattended session, a thrown-away memory card. How scavenging recovers what you thought was gone.
Read More
Separation of Duties: How Can Separation of Duties Prevent Fraud?
By Charles Joseph · Updated
Bank loans, retail operations and software development all divide the power. How separation of duties prevents fraud.
Read More
Sensitive Information: How to Protect Sensitive Information Online?
By Charles Joseph · Updated
Social Security numbers, medical records, bank details. What counts as sensitive, and how to protect it online.
Read More
Segment: How Does Network Segmentation Improve Security?
By Charles Joseph · Updated
A large office network, a home network. How segments isolate parts of a network, and how that improves security.
Read More
Secure Sockets Layer (SSL): How Reliable Is SSL Encryption?
By Charles Joseph · Updated
An encrypted link between browser and server, for shopping, social media and banking. How SSL works, and how reliable it is.
Read More
Resource Exhaustion: How Can It Lead to Denial of Service?
By Charles Joseph · Updated
A website overwhelmed, a computer overburdened, an email server saturated. How resource exhaustion leads to denial of service.
Read More
Reverse Address Resolution Protocol (RARP): What Is Its Purpose?
By Charles Joseph · Updated
A device knows its hardware address but needs an IP. How RARP answers, for booting computers, printers and large networks.
Read More
Reverse Engineering: How Can It Pose a Security Risk?
By Charles Joseph · Updated
Dissecting a virus, studying a competitor's product, enhancing old software. How reverse engineering works, and the security risks it poses.
Read More
Reverse Proxy: How Does It Enhance Network Security?
By Charles Joseph · Updated
A server in front of your web server, balancing load and encrypting traffic. How reverse proxies protect company sites, streaming platforms and banks.
Read More
Risk Averse: How Does It Impact Cybersecurity Decisions?
By Charles Joseph · Updated
Bonds, insurance and health decisions. What risk aversion means, and how it shapes cybersecurity choices.
Read More
Role Based Access Control: How Effective Is Role Based Access Control?
By Charles Joseph · Updated
HR staff, customer service reps and IT managers each get a different key. How role-based access control works, and how effective it is.
Read More
Rivest-Shamir-Adleman (RSA): How Secure Is It?
By Charles Joseph · Updated
Two large primes multiplied, nearly impossible to factor back. How RSA secures email, e-commerce and internal communications, and how secure it is.
Read More
Request for Comment (RFC): What Is Its Role in Internet Standards?
By Charles Joseph · Updated
RFC 791, 2616 and 5322 defined IP, HTTP and email. What RFCs are, and their role in internet standards.
Read More
Proxy Server: How Does It Increase Online Anonymity?
By Charles Joseph · Updated
School networks, organizations and personal browsing. How proxy servers work, and how they increase anonymity.
Read More
Regression Analysis: How Is It Used in Cybersecurity?
By Charles Joseph · Updated
Sales forecasts, real estate prices, health spending. How regression analysis predicts outcomes, and how it's used in cybersecurity.
Read More
Race Condition: How Can It Be Exploited in Cybersecurity?
By Charles Joseph · Updated
Two operations, one wrong order. How race conditions break ticket booking, bank transactions and file operations, and how attackers exploit them.
Read More
Radiation Monitoring: How Does It Impact Security?
By Charles Joseph · Updated
Nuclear plants, hospital radiology and the environment. What radiation monitoring is, and how it relates to security.
Read More
Reconnaissance: How Does It Precede Cyber Attacks?
By Charles Joseph · Updated
Website traffic, phishing emails and network scans. How reconnaissance gathers intelligence before an attack.
Read More
Reflexive ACLs (Cisco): How Do They Enhance Network Security?
By Charles Joseph · Updated
Open the gate briefly for return traffic, then close it. How reflexive ACLs protect VPNs, browsing and email on Cisco systems.
Read More
Registry: What Are Its Implications on System Security?
By Charles Joseph · Updated
The Windows database behind installations, settings and background processes. What the registry stores, and why it matters for security.
Read More
Possession: How Can It Compromise Cybersecurity?
By Charles Joseph · Updated
Your phone, a company server, a security key. How possession fits into information access, and how it can be compromised.
Read More
-version-3-pop3: What Enhancements Does It Bring?
By Charles Joseph · Updated
Download the mail, delete it from the server. How POP3 works in email clients like Outlook, and what version 3 brought.
Read More
Preamble: What Is Its Role in Networking?
By Charles Joseph · Updated
A heads-up before the data arrives. How preambles work in wireless, Ethernet and radio communication.
Read More
Private Addressing: How Does It Protect Network Identity?
By Charles Joseph · Updated
Addresses that work inside the network but never on the internet. How private addressing protects homes, offices and campuses.
Read More
Program Infector: How Does It Spread Malware?
By Charles Joseph · Updated
A game, a Word file, a music program. How program infectors ride along with executables and spread malware.
Read More
Program Policy: What Role Does It Play in Cybersecurity?
By Charles Joseph · Updated
Backups, passwords and internet use. What program policies cover, and their role in cybersecurity.
Read More
Promiscuous Mode: What Are Its Potential Risks?
By Charles Joseph · Updated
A network card that reads every packet, not just its own. How promiscuous mode helps troubleshooting and intrusion detection, and the risks.
Read More
Proprietary Information: How Can It Be Protected?
By Charles Joseph · Updated
A secret recipe, a customer database, a business strategy. What proprietary information is, and how to protect it.
Read More
Port Scan: How Can It Reveal Network Vulnerabilities?
By Charles Joseph · Updated
Which doors are open and what's behind them. How port scans work for admins and hackers alike.
Read More
Port: What Makes It a Potential Entry Point for Attacks?
By Charles Joseph · Updated
Over 65,000 doors on every connected machine. How ports organize traffic, and why open ones are a favorite entry point.
Read More
Polymorphism: Why Is It a Threat in Malware?
By Charles Joseph · Updated
Malware that rewrites itself every time it spreads. Why polymorphic code slips past antivirus, with examples from email to piracy.
Read More
Payload: What Does It Carry in a Cyberattack?
By Charles Joseph · Updated
The part of the malware that actually does the damage. Ransomware, trojan and destructive payloads, explained.
Read More
Permutation: How Does It Strengthen Cryptography?
By Charles Joseph · Updated
Three books on a shelf, a locker combination, a race result. How permutations work, and why counting arrangements strengthens cryptography.
Read More
Personal Firewalls: Are They Effective Enough?
By Charles Joseph · Updated
A remote worker, a small business owner, a gamer. How personal firewalls protect individual computers, and whether they're enough.
Read More
Pharming: How Can It Be Detected and Prevented?
By Charles Joseph · Updated
You typed the right address and still landed on a fake bank. How pharming redirects you, and how to detect and prevent it.
Read More
Ping of Death: How Can It Disrupt Services?
By Charles Joseph · Updated
One oversized ping packet can crash a machine. How the ping of death works, from network crashes to ruined gaming sessions.
Read More
Ping Scan: How Does It Help in Network Discovery?
By Charles Joseph · Updated
Send a ping to every address and see who answers. How ping scans help with troubleshooting, mapping and monitoring.
Read More
Ping Sweep: What Makes It a Useful Reconnaissance Tool?
By Charles Joseph · Updated
Which machines are alive on the network? How ping sweeps answer that, for admins and for attackers.
Read More
Point-to-Point Protocol (PPP): What Are Its Security Implications?
By Charles Joseph · Updated
Dial-up connections, file transfers and remote offices. How PPP links two nodes, and the security implications.
Read More
Point-to-Point Tunneling Protocol (PPTP): How Secure Is It?
By Charles Joseph · Updated
A Microsoft-led VPN protocol for remote workers, students abroad and privacy seekers. How PPTP works, and how secure it is today.
Read More
Polyinstantiation: How Does It Protect Database Integrity?
By Charles Joseph · Updated
Two records with the same name and different secrets. How polyinstantiation protects databases in hospitals, social media and corporate records.
Read More
One-Way Function: What Makes It Irreversible?
By Charles Joseph · Updated
Mash a potato or shred a document and there's no putting it back. How one-way functions underpin cryptographic hashing.
Read More
One-Way Encryption: Is It Secure Enough?
By Charles Joseph · Updated
Encrypt it, and nobody can turn it back, not even you. How one-way encryption protects passwords, and whether it's secure enough.
Read More
Octet: How Is It Used in IP Addresses?
By Charles Joseph · Updated
Eight bits, always. How octets make up IP addresses, file sizes and UTF-8 text, and how they differ from bytes.
Read More
Null Session: What Are Its Potential Risks?
By Charles Joseph · Updated
A connection to a Windows machine with no username and no password. What null sessions allow, and the risks they open.
Read More
What Are Network Taps?
By Charles Joseph · Updated
A two-way mirror for network traffic. How TAPs copy every packet for monitoring, performance checks and forensics.
Read More
OSI: Why Is It Important to Understand It?
By Charles Joseph · Updated
Seven layers from physical cable to application. What the OSI model is, and why understanding it makes everything else in networking clearer.
Read More
OSI Layers: What Role Does Each Layer Play?
By Charles Joseph · Updated
Physical, data link, network and the four above them. What each OSI layer does, and why the model still shapes how networks are taught.
Read More
Overload: How Can It Affect Network Performance?
By Charles Joseph · Updated
Too many users, too many apps, too much traffic. How overload slows and breaks servers, devices and networks.
Read More
Packet: What Makes It Crucial for Data Transmission?
By Charles Joseph · Updated
Email, video and web pages all travel in small pieces with addresses attached. What a packet carries, and why nothing moves without them.
Read More
Packet Switched Network: Why Choose It Over Circuit Switching?
By Charles Joseph · Updated
Email, Skype calls and streaming all share the same lines by breaking data into packets. Why packet switching beat circuit switching.
Read More
Partitions: How Do They Increase System Security?
By Charles Joseph · Updated
One drive, several compartments. How partitions organize storage, run multiple operating systems and keep a crash from taking everything.
Read More
Password Authentication Protocol (PAP): Is It Safe Enough?
By Charles Joseph · Updated
Username and password sent in plain text, still used in email setup and ISP access. Why PAP is simple, and why that's a problem.
Read More
Password Cracking: How Is It Achieved?
By Charles Joseph · Updated
Brute force, dictionary attacks and keyloggers. How passwords get cracked, and what that means for yours.
Read More
Patching: How Does It Improve Software Security?
By Charles Joseph · Updated
Your phone, your games and your operating system all get patched. How patching closes holes before attackers find them.
Read More
Network-Based IDS: How Effective Is It?
By Charles Joseph · Updated
A system that watches all the traffic for anything that breaks the rules. How network-based intrusion detection protects businesses, shops and schools.
Read More
Network Address Translation: How Does It Improve Security?
By Charles Joseph · Updated
Home Wi-Fi, corporate networks and online games all share public addresses through NAT. How translation works, and how it improves security.
Read More
Logic Gate: What Is Its Role in Computer Security?
By Charles Joseph · Updated
AND, OR, NOT: the switches behind every computation. What logic gates are, and where they fit into computer security.
Read More
Logic Bombs: How Are They Triggered?
By Charles Joseph · Updated
Code that sits quietly until a date, an event or a departure sets it off. How logic bombs are planted by employees, in games and in school records.
Read More
Loopback Address: What Is Its Purpose?
By Charles Joseph · Updated
127.0.0.1 is the address a computer uses to talk to itself. How the loopback address helps with health checks, development and troubleshooting.
Read More
MAC Address: Can It Be Spoofed?
By Charles Joseph · Updated
Your Wi-Fi, your Bluetooth headphones and the office printer each carry a hardware address. What a MAC address is, and whether it can be faked.
Read More
Man-in-the-Middle Attack (MitM): How Can It Be Avoided?
By Charles Joseph · Updated
Someone sits between you and the site, reading and changing everything. How MitM attacks hit email, shopping and Wi-Fi, and how to avoid them.
Read More
Mandatory Access Control (MAC): Why Is It Necessary?
By Charles Joseph · Updated
Clearance levels and classifications decide who sees what, no exceptions. How mandatory access control works in government, hospitals and companies.
Read More
Masquerade Attack: How Can It Be Prevented?
By Charles Joseph · Updated
Phishing emails, fake Wi-Fi and spoofed caller ID all pretend to be someone you trust. How masquerade attacks work, and how to prevent them.
Read More
md5: Is It Still Secure?
By Charles Joseph · Updated
Designed by Ronald Rivest in 1991 and still everywhere. How MD5 verifies files and transmissions, and whether it has any business protecting passwords.
Read More
Measures of Effectiveness (MOE): How Are They Assessed?
By Charles Joseph · Updated
Customer satisfaction, project time, sales numbers. How measures of effectiveness tell you whether a strategy is actually working.
Read More
Natural Disaster: How Can It Affect Cybersecurity?
By Charles Joseph · Updated
Hurricanes, earthquakes and floods don't care about firewalls. How natural disasters affect cybersecurity, and what to plan for.
Read More
National Institute of Standards and Technology (NIST): What Is Its Role?
By Charles Joseph · Updated
The cybersecurity framework, the secure hash standard, post-quantum crypto. What NIST does, and why its guidelines reach so far.
Read More
Multiplexing: How Does It Improve Network Efficiency?
By Charles Joseph · Updated
Radio stations, cable TV and phone networks all squeeze many signals into one line. How multiplexing works, and why efficiency is the point.
Read More
Multi-Homed: What Are Its Advantages?
By Charles Joseph · Updated
Two connections instead of one, for business systems, home entertainment and data center servers. What multi-homing buys you.
Read More
Multi-Cast: How Does It Work in Networks?
By Charles Joseph · Updated
One packet, many receivers. How multicast powers video conferencing, live streams and IPTV without flooding the network.
Read More
Monoculture: Does It Impact Cybersecurity?
By Charles Joseph · Updated
Same operating system, same storage, same protocols everywhere. Why uniformity is efficient, and why one key then opens every door.
Read More
Internet Engineering Task Force (IETF): Why Is It Significant?
By Charles Joseph · Updated
HTTP/2, IPv6 and TLS all came out of one open community. What the IETF is, and why its standards shape your every connection.
Read More
Internet Control Message Protocol (ICMP): How Does It Work?
By Charles Joseph · Updated
Destination unreachable, time exceeded, ping. How ICMP carries the internet's error messages and status checks.
Read More
Internet: Is It Truly Secure?
By Charles Joseph · Updated
Email, social media and shopping all ride on one global network of networks. What the internet is, and whether it was ever built to be secure.
Read More
Integrity Star Property: Why Is It Important?
By Charles Joseph · Updated
Nobody writes upward. Why the star property keeps lower-level users from altering higher-level data, in companies, schools and hospitals.
Read More
Ingress Filtering: What Is Its Security Impact?
By Charles Joseph · Updated
Check that incoming traffic really comes from where it claims. How ingress filtering stops spoofed packets at the company, the ISP and at home.
Read More
Information Warfare: Is It a Real Threat?
By Charles Joseph · Updated
Propaganda, hacking and social engineering as weapons. What information warfare looks like, and whether it's a real threat or a buzzword.
Read More
Internet Message Access Protocol (IMAP): What Are Its Security Risks?
By Charles Joseph · Updated
Read an email on your phone, delete it on your laptop, and both agree. How IMAP keeps devices in sync, and the security risks that come with it.
Read More
Internet Protocol (IP): How Secure Is It?
By Charles Joseph · Updated
Emailing, browsing and video calls all depend on packets finding their way. How IP addresses and routes data, and how secure the system is.
Read More
Kernel: What Is Its Role in Cybersecurity?
By Charles Joseph · Updated
Opening an app, saving a file, playing a game: the kernel is in the middle of all of it. What the operating system's core does, and why its security matters most.
Read More
Lattice Techniques: How Do They Enhance Security?
By Charles Joseph · Updated
A mathematical grid so complex that even quantum computers struggle with it. How lattice techniques secure encryption and signatures, and why they're the future.
Read More
Layer 2 Forwarding Protocol (L2F): How Does It Operate?
By Charles Joseph · Updated
Cisco's tunneling protocol for VPNs, carrying PPP frames across IP networks. How L2F works for remote workers and international connections.
Read More
Layer 2 Tunneling Protocol (L2TP): Why Use It?
By Charles Joseph · Updated
A tunnel between two points, paired with IPsec for security. Why L2TP is used for remote work, safe browsing and getting past geo-blocks.
Read More
Least Privilege: Why Is It a Good Practice?
By Charles Joseph · Updated
A customer service rep, an intern and a social media manager each get only what the job needs. Why least privilege limits the damage when things go wrong.
Read More
Legion: What Is Its Impact on Cybersecurity?
By Charles Joseph · Updated
An open-source penetration testing tool that maps subnets, detects services and visualizes the results. How Legion is used in corporate, freelance and university settings.
Read More
Lightweight Directory Access Protocol (LDAP): How Safe Is It?
By Charles Joseph · Updated
Email apps, single sign-on and phone directories all lean on it. How LDAP organizes network data, and how safe it is.
Read More
Link State: How Is It Used in Routing?
By Charles Joseph · Updated
Every router keeps a map of the whole network and picks the best path. How link state routing works, with examples.
Read More
List Based Access Control: What Makes It Efficient?
By Charles Joseph · Updated
Premium content, company databases and private forums all keep a list of who gets in. How list-based access control works, and what makes it efficient.
Read More
Kerberos: How Secure Is This Authentication Protocol?
By Charles Joseph · Updated
Named after a three-headed dog, built on tickets rather than passwords on the wire. How Kerberos works in universities, enterprises and Wi-Fi, and how secure it is.
Read More
Jitter: How Does It Affect Network Performance?
By Charles Joseph · Updated
Packets that arrive at uneven intervals make video calls stutter and games lag. What jitter is, and why lower is better.
Read More
Internet Protocol Security (IPsec): Why Use It?
By Charles Joseph · Updated
Encryption and signing at the IP layer, so VPNs, data transfers and email stay private. Why IPsec exists and when to use it.
Read More
Internet Standard: Who Sets Them?
By Charles Joseph · Updated
HTTP, IP and FTP work the same everywhere because someone wrote it down. Who sets internet standards, and how.
Read More
Interrupt: How Can It Influence a System?
By Charles Joseph · Updated
A keypress, incoming network data, a power failure. How interrupts make the operating system drop everything, and how that can be abused.
Read More
Intranet: How Safe Is It from External Threats?
By Charles Joseph · Updated
A private internet for the company, campus or hospital. How intranets work, and how safe they really are from the outside world.
Read More
IP Address: Can It Be Traced?
By Charles Joseph · Updated
Your laptop at home, a company website, your phone on the mobile network. What an IP address is, and whether it can be traced back to you.
Read More
IP Flood: How Can It Disrupt Services?
By Charles Joseph · Updated
An online store, a business announcement, a public service, each buried under spoofed traffic. How IP floods disrupt services and why they're hard to trace.
Read More
IP Forwarding: How Does It Work?
By Charles Joseph · Updated
Home Wi-Fi, office networks and online games all rely on routers deciding where packets go next. How IP forwarding works.
Read More
IP Spoofing: How Can It Be Prevented?
By Charles Joseph · Updated
Traffic that claims to come from somewhere it doesn't. How IP spoofing powers phishing, DDoS and unauthorized access, and how to prevent it.
Read More
ISO: How Does It Impact Cybersecurity Standards?
By Charles Joseph · Updated
ISO 9001, 14001 and 27001 set the bar for quality, environment and security. How the standards body shapes cybersecurity.
Read More
ITU-T: How Does It Contribute to Cybersecurity?
By Charles Joseph · Updated
The UN's telecom standards body, behind the G, V and H series recommendations. What ITU-T does, and how it contributes to cybersecurity.
Read More
Hybrid Attack: How Does It Threaten Cybersecurity?
By Charles Joseph · Updated
A dictionary attack first, brute force second. How hybrid attacks crack passwords on encryption programs, bank platforms and social accounts.
Read More
HTTPS: Why Is It More Secure?
By Charles Joseph · Updated
Shopping, banking, email and social media all run on it. Why the S makes a difference, and how HTTPS keeps your data private.
Read More
HTTP Proxy: How Does It Safeguard Privacy?
By Charles Joseph · Updated
Jane wants privacy, so her requests go through a middleman. How HTTP proxies hide your details from the sites you visit.
Read More
Host-Based ID: What Makes It Essential?
By Charles Joseph · Updated
Antivirus, a firewall and a log monitor, all watching one machine. What host-based intrusion detection does, and why it's essential.
Read More
Hops: How Do Hops Impact Network Performance?:0
By Charles Joseph · Updated
An email from New York to Los Angeles doesn't travel in a straight line. How hops work, and why fewer is faster.
Read More
Host: What Defines a Computer Host?
By Charles Joseph · Updated
An email server, a personal computer, a website server. What makes a device a host, and what hosts do on a network.
Read More
Hybrid Encryption: Why the Hybrid Approach?
By Charles Joseph · Updated
Symmetric speed plus asymmetric security. How hybrid encryption protects email, websites and file transfers.
Read More
Hyperlink: What Risks Do Hyperlinks Carry?
By Charles Joseph · Updated
One click takes you anywhere. What hyperlinks are, and the risks hiding behind the blue text.
Read More
Hypertext Transfer Protocol (HTTP): Why Not HTTPS?
By Charles Joseph · Updated
Plain HTTP sends everything in the clear, for anyone on the path to read. How a request to www.example.com travels, and why the S matters.
Read More
Identity: What Makes It Vulnerable Online?
By Charles Joseph · Updated
Your email, your social profiles, your bank login: each is a version of you that someone might want. What digital identity is, and what makes it vulnerable.
Read More
Incremental Backups: Are They Efficient Enough?
By Charles Joseph · Updated
Copy only what changed since last time. How incremental backups save space and time at work, in photo editing and in programming, and what they cost you later.
Read More
Inetd (xinetd): How Is It Utilized?
By Charles Joseph · Updated
The Unix superserver that wakes FTP, telnet and POP3 only when someone knocks. How inetd and xinetd manage services and save resources.
Read More
Inference Attack: How Dangerous Can It Be?
By Charles Joseph · Updated
Public medical data here, shopping habits there, and suddenly the picture is private. How inference attacks piece together what no single source reveals.
Read More
Honeymonkey: What Is the Role of a Honeymonkey in Security?
By Charles Joseph · Updated
A virtual machine that surfs the web as bait. How honeymonkeys catch malicious sites for e-commerce, government and social media.
Read More
Honey Client: How Does a Honey Client Contribute to Security?
By Charles Joseph · Updated
A program that browses the web like a person, looking for sites that bite. How honey clients find threats before real users do.
Read More
Fragment Overlap Attack: How Damaging Can a Fragment Overlap Attack Be?
By Charles Joseph · Updated
Sarah sends overlapping fragments and the target's system puts them together wrong. How fragment overlap attacks slip malicious payloads past defenses.
Read More
Fragmentation: What Role Does Fragmentation Play in Network Communication?
By Charles Joseph · Updated
Big attachments, video streams and downloads all get split into pieces for the trip. How fragmentation works and why the pieces matter.
Read More
Full Duplex: How Does Full Duplex Enhance Communication?
By Charles Joseph · Updated
Both sides talk and listen at once, like a phone call. How full duplex speeds up video chat, radios and data transfer.
Read More
Fully-Qualified Domain Name: Why Use a Fully-Qualified Domain Name?
By Charles Joseph · Updated
Host, subdomain, domain and top-level domain, all spelled out. What an FQDN is, and why precision matters.
Read More
Fuzzing: How Effective Is Fuzzing in Finding Security Flaws?
By Charles Joseph · Updated
Throw random garbage at a program and see what breaks. How fuzzing finds flaws in web apps, email clients and firewalls.
Read More
Gateway: How Essential Are Gateways in Networking?
By Charles Joseph · Updated
Your home router, a corporate email server, a payment processor. How gateways translate between networks, and why nothing connects without them.
Read More
gethostbyaddr: What Security Implications Does gethostbyaddr Have?
By Charles Joseph · Updated
Give it an IP address and it hands back a hostname. How gethostbyaddr helps with traffic analysis and troubleshooting, and how it can be abused.
Read More
gethostbyname: What Information Can gethostbyname Reveal?
By Charles Joseph · Updated
The function that turns www.example.com into a number your computer can use. What gethostbyname reveals, from browsing to command-line tools.
Read More
GNU: How Has GNU Contributed to Open Source Security?
By Charles Joseph · Updated
GCC, Bash and Emacs are all GNU. How Richard Stallman's free software project shaped open source, and what that did for security.
Read More
Hardening: Why Is System Hardening Essential for Security?
By Charles Joseph · Updated
Update everything, lock down the firewall, trim user permissions. How hardening shrinks what an attacker can reach.
Read More
Hash Function: How Secure Are Hash Functions?
By Charles Joseph · Updated
Any input, one fixed-size output, and no way back. How hash functions verify documents, protect passwords and run Bitcoin, and how secure they are.
Read More
Header: How Important Are Headers in Cybersecurity?
By Charles Joseph · Updated
Email headers, webpage headers, document headers. What they contain, and why investigators read them first.
Read More
File Transfer Protocol (FTP): How Secure Is File Transfer Protocol?
By Charles Joseph · Updated
Uploading a website, downloading files, sharing content. How FTP moves data, and how much you can trust it with yours.
Read More
Fault Line Attacks: What Are Fault Line Attacks and How Damaging Can They Be?
By Charles Joseph · Updated
Unpatched software, weak passwords and misconfigured settings. How attackers find the small cracks, and how much damage follows.
Read More
Fast Flux: How Does Fast Flux Aid Cybercriminals?
By Charles Joseph · Updated
The malicious site keeps moving its address faster than anyone can block it. How fast flux hides phishing, spam and botnet controls.
Read More
Fast File System: How Does a Fast File System Improve System Performance?
By Charles Joseph · Published
Bigger blocks, smarter layout, faster disks. How a fast file system speeds up PCs, businesses and photo editing.
Read More
False Rejects: How Do False Rejects Affect Biometric Systems?
By Charles Joseph · Updated
Your phone won't recognize your face, your bank won't accept your login. Why biometric systems turn away the right people, and what it costs.
Read More
Exterior Gateway Protocol (EGP): What Is the Function of Exterior Gateway Protocol?
By Charles Joseph · Updated
Networks need a way to talk to other networks. What exterior gateway protocols do, with BGP as the famous example.
Read More
Filter: How Crucial Are Filters in Cybersecurity?
By Charles Joseph · Updated
Email filters, web filters and network filters all do the same job: let the good through, stop the bad. How crucial they are, with examples.
Read More
Filtering Router: What Role Does a Filtering Router Play?
By Charles Joseph · Updated
A router that inspects every packet against the rules before letting it pass. How online shops, universities and companies use one.
Read More
Fingerprinting: How Does Fingerprinting Aid Cybercriminals?
By Charles Joseph · Updated
Your browser, your phone and your network each leave a unique trace. How fingerprinting identifies devices, and how criminals use it.
Read More
Flooding: How Damaging Can Flooding Attacks Be?
By Charles Joseph · Published
An online store, a chat app and an email service, each buried under traffic until they stop responding. How flooding attacks work and what they cost.
Read More
Fork Bomb: What Damage Can a Fork Bomb Cause?
By Charles Joseph · Updated
A single line of symbols that can bring a system to its knees. How fork bombs work in Bash, Python and Windows, and the damage they do.
Read More
Form-Based Authentication: Is Form-Based Authentication Still Safe?
By Charles Joseph · Updated
The login box on every social platform, email service and bank. How form-based authentication works, and whether it's still safe.
Read More
Forward Lookup: How Does a Forward Lookup Function in DNS?
By Charles Joseph · Updated
Type a name, get an address. How forward lookups let you browse, send email and build sites locally.
Read More
Forward Proxy: How Does a Forward Proxy Protect User Privacy?
By Charles Joseph · Updated
A server that stands between you and the internet, hiding who you are. How forward proxies work at the office, for anonymous browsing and for geo-blocked content.
Read More
Finger: What Security Implications Does the Finger Protocol Have?
By Charles Joseph · Updated
An old Unix tool that tells you who's logged in and when. What finger reveals, and why that's a security problem.
Read More
Extensible Authentication Protocol (EAP): How Secure Is Extensible Authentication Protocol?
By Charles Joseph · Updated
A framework that lets Wi-Fi, remote access and point-to-point links prove who's connecting. How EAP works, and how secure it is.
Read More
Extended ACLs (Cisco): How Do Extended ACLs Enhance Network Security?
By Charles Joseph · Updated
Filter by source, destination, protocol and port, not just by address. How extended ACLs protect data, limit FTP and permit email.
Read More
Exponential Backoff Algorithm: How Does Exponential Backoff Algorithm Ensure Network Stability?
By Charles Joseph · Updated
Fail, wait, try again, wait twice as long. How exponential backoff keeps email, Wi-Fi and traffic systems from collapsing under load.
Read More
Domain Name System (DNS): How Crucial Is DNS Security?
By Charles Joseph · Updated
The phone book of the internet, consulted every time you open YouTube, Amazon or Facebook. How DNS works, and why its security matters so much.
Read More
Due Care: Why Is Due Care Critical in Cybersecurity?
By Charles Joseph · Updated
What would a reasonable person do to protect the business? How due care shows up in retail security, staff training and routine monitoring.
Read More
Due Diligence: How Does Due Diligence Impact Cybersecurity?
By Charles Joseph · Updated
Launching an app, picking a cloud provider, buying a company. How due diligence checks the risks before you commit, and what it means for security.
Read More
Dumpster Diving: How Effective Is Dumpster Diving in Gathering Information?
By Charles Joseph · Updated
Bank statements, company records and medical files, found in the trash. How dumpster diving still works, and how to stop feeding it.
Read More
Dynamic Link Library: What Risks Do Dynamic Link Libraries Pose?
By Charles Joseph · Updated
Files like user32.dll let many programs share the same code. What DLLs do, and the risks that come with sharing.
Read More
Dynamic Routing Protocol: How Does Dynamic Routing Protocol Enhance Network Efficiency?
By Charles Joseph · Updated
Routers talk to each other and reroute when a link dies. How BGP, OSPF and RIP keep traffic moving without anyone touching a config.
Read More
Fragment Offset: What Is the Purpose of Fragment Offset?
By Charles Joseph · Updated
A sofa won't fit through the door in one piece, and neither will a big packet. How fragment offset puts the pieces back in order.
Read More
Echo Reply: What Information Can an Echo Reply Reveal?
By Charles Joseph · Updated
I'm here and I can hear you. What a ping response tells you, from your home network to the game server.
Read More
Echo Request: How Can Echo Requests Aid in Network Troubleshooting?
By Charles Joseph · Updated
Ping first, then see who answers. How echo requests test connections at home, in the office and across the internet.
Read More
Ethernet: How Secure Is Ethernet Networking?
By Charles Joseph · Updated
The cables under the office floor, behind your TV and in the internet café. How Ethernet works, and how secure a wired network really is.
Read More
Escrow Passwords: What Are the Risks with Password Escrows?
By Charles Joseph · Updated
A trusted third party keeps a copy of the password in case you lose it. How escrow works for company backups, code and family photos, and the risks of trusting the keeper.
Read More
Ephemeral Port: What Is the Purpose of Ephemeral Ports?
By Charles Joseph · Updated
Every website visit, FaceTime call and email opens a short-lived port that closes when it's done. What ephemeral ports are for.
Read More
Encapsulation: How Does Encapsulation Enhance Data Transmission?
By Charles Joseph · Updated
A coffee machine hides its complexity behind a few buttons. How encapsulation does the same for code, in banking software and self-driving cars.
Read More
Emanations Analysis: How Effective Is Emanations Analysis in Espionage?
By Charles Joseph · Updated
Monitors radiate, keyboards click, wireless devices leak. How emanations analysis turns stray signals into stolen information.
Read More
Egress Filtering: How Does Egress Filtering Enhance Network Security?
By Charles Joseph · Updated
Most people guard what comes in. Egress filtering guards what goes out. How it stops data leaks and malware calling home, at work and on public Wi-Fi.
Read More
Dictionary Attack: How Effective Are Dictionary Attacks Today?
By Charles Joseph · Updated
Every word in the dictionary, tried one after another, against your email, your Wi-Fi and your social accounts. How well it still works today.
Read More
Diffie-Hellman: Why Use the Diffie-Hellman Key Exchange?
By Charles Joseph · Updated
Alice and Bob agree on a secret while everyone listens, and nobody else can work it out. Why Diffie-Hellman underpins online banking and secure Wi-Fi.
Read More
Digest Authentication: How Does Digest Authentication Improve Security?
By Charles Joseph · Updated
The server sends a random number, and you answer with a hash instead of your password. How digest authentication protects web content, networks and APIs.
Read More
Digital Envelope: How Secure Is a Digital Envelope?
By Charles Joseph · Updated
Lock the message with a one-time key, then lock the key with the recipient's public key. How digital envelopes secure email, banking and online shopping.
Read More
Digital Signature Algorithm (DSA): How Reliable Is the Digital Signature Algorithm?
By Charles Joseph · Updated
Sign with the private key, verify with the public one. How DSA vouches for email, software and documents, and how reliable it is.
Read More
Digital Signature Standard (DSS): How Does DSS Enhance Document Security?
By Charles Joseph · Updated
The federal standard behind digital signatures. What DSS requires, and how it secures email, software updates and online transactions.
Read More
Disassembly: What Is the Purpose of Disassembly in Malware Analysis?
By Charles Joseph · Updated
Machine code goes in, something a human can read comes out. How disassembly powers reverse engineering, malware analysis and bug hunting.
Read More
Disaster Recovery Plan (DRP): How Essential Is a DRP for Businesses?
By Charles Joseph · Updated
A crashed server, a power outage, a breach. What a disaster recovery plan covers, and why businesses without one rarely get a second chance.
Read More
Discretionary Access Control (DAC): What Are the Risks in Discretionary Access Control?
By Charles Joseph · Updated
You decide who can open your document, see your post or read your mail. How discretionary access control works, and the risks of leaving it to users.
Read More
Distance Vector: How Does Distance Vector Routing Work?
By Charles Joseph · Updated
Message runners in a village, counting the steps to each neighbor. How distance vector routing finds a path, explained with examples.
Read More
Distributed Scans: How Dangerous Are Distributed Scans?
By Charles Joseph · Updated
Spread the scan across many machines and no single alarm goes off. How distributed scans probe corporate networks, security systems and game servers.
Read More
Domain Hijacking: How Prevalent Is Domain Hijacking?
By Charles Joseph · Updated
Someone else now controls your website's name, and your visitors are going wherever they send them. How domain hijacking happens, and how common it is.
Read More
Demilitarized Zone (DMZ): How Does a DMZ Improve Network Security?
By Charles Joseph · Updated
Your public web server sits in a buffer zone where an attacker can reach it but go no further. How a DMZ protects a business, a campus and a mobile app.
Read More
Defense In-Depth: Why Is Defense In-Depth Strategy Important?
By Charles Joseph · Updated
No single wall holds forever, so you build several. How antivirus, firewalls, training and email filtering stack up into defense in depth.
Read More
Covert Channels: How Do Covert Channels Pose a Security Risk?
By Charles Joseph · Updated
Secrets can leak through timing, hidden traffic and the metadata of a file. How covert channels carry data where no channel should exist.
Read More
Crimeware: What Dangers Does Crimeware Pose?
By Charles Joseph · Updated
Spyware, ransomware and keyloggers are built for one purpose: breaking the law. What crimeware does, and the dangers it poses to you.
Read More
Cron: How Does Cron Contribute to System Automation?
By Charles Joseph · Updated
Backups at midnight, updates every Sunday, a website checked every five minutes. How cron keeps Unix systems running on schedule.
Read More
Crossover Cable: What Purpose Does a Crossover Cable Serve?
By Charles Joseph · Updated
Two computers, one cable, no switch required. What a crossover cable does, and when it still comes in handy for transfers, gaming and troubleshooting.
Read More
Cryptographic Algorithm or Hash: How Secure Are Cryptographic Algorithms or Hashes?
By Charles Joseph · Updated
A fingerprint for data that can't be reversed. How hashes protect passwords, verify files and hold blockchains together.
Read More
Cut-Through: How Does Cut-Through Impact Network Speed?
By Charles Joseph · Updated
The switch starts forwarding before the packet has fully arrived. How cut-through speeds up email, video and gaming, and what it risks.
Read More
Cyclic Redundancy Check (CRC): How Does CRC Ensure Data Integrity?
By Charles Joseph · Updated
A short code attached to every block of data catches errors in transit. How CRC works for downloads, disks and networks.
Read More
Daemon: What Is the Role of Daemons in Systems?
By Charles Joseph · Updated
Print jobs, email and system logs are handled by programs you never see. What a daemon is, and why systems depend on these quiet helpers.
Read More
Defacement: How Damaging Can Web Defacement Be?
By Charles Joseph · Updated
Visitors arrive at the library's website and find a hacker's message instead. What defacement is, and the damage it does to trust.
Read More
Datagram: How Does Datagram Communication Work?
By Charles Joseph · Updated
A self-contained package with the address on the outside, sent without waiting for a handshake. How datagrams carry email, games and video calls.
Read More
Data Warehousing: How Secure Are Data Warehouses?
By Charles Joseph · Updated
Retailers, hospitals and banks pour years of records into one place. What a data warehouse does, and whether that much data in one spot can be kept safe.
Read More
Data Owner: What Responsibilities Does a Data Owner Hold?
By Charles Joseph · Updated
A shop owner, a researcher, a social platform. Who owns data, what they're responsible for, and what happens when they get it wrong.
Read More
Challenge-Handshake Authentication Protocol (CHAP): How Secure Is CHAP?
By Charles Joseph · Updated
Prove you know the password without ever sending it. How CHAP's challenge-and-response works for ISPs and remote access, and how secure it really is.
Read More
Checksum: How Does Checksum Ensure Data Integrity?
By Charles Joseph · Updated
Change a single bit and the number no longer matches. How checksums catch corrupted downloads, bad storage and garbled network traffic.
Read More
Circuit Switched Network: What Are the Advantages of a Circuit Switched Network?
By Charles Joseph · Updated
A dedicated line from one end to the other, like an old-fashioned phone call. How circuit switching works, from landlines to dial-up and fax.
Read More
Client: How Does Client-side Security Impact Overall Cybersecurity?
By Charles Joseph · Updated
Your browser, your email app and your game are all clients asking servers for something. What the client does, and why securing it matters to the whole picture.
Read More
Cold/Warm/Hot Disaster Recovery Site: What Differentiates a Cold
By Charles Joseph · Updated
An empty building, a partly stocked one, or a mirror ready to switch on. The three kinds of recovery site, and what each costs in money and time.
Read More
Collision: How Does Collision Affect Network Efficiency?
By Charles Joseph · Updated
Two different inputs, one identical hash. Why collisions happen, what they mean for security, and three everyday examples of the same problem.
Read More
Competitive Intelligence: How Ethical Is Competitive Intelligence?
By Charles Joseph · Updated
Knowing what the coffee shop across the street is planning is smart business. How competitive intelligence works, and where it stops being ethical.
Read More
Computer Emergency Response Team (CERT): What Role Does CERT Play in Cybersecurity Response?
By Charles Joseph · Updated
When a breach hits, a CERT is the team that knows what to do first. How they operate inside companies, at national level and on campus.
Read More
Computer Network: How Vulnerable Are Computer Networks to Cyber Attacks?
By Charles Joseph · Updated
Your home Wi-Fi, the office LAN and the internet itself are all networks. What connects them, and how exposed each one is to attack.
Read More
Cookie: How Do Cookies Affect User Privacy?
By Charles Joseph · Updated
Websites remember you, your cart and your login thanks to tiny files on your computer. What cookies store, and what they tell others about you.
Read More
Corruption: How Does Corruption Impact Cybersecurity?
By Charles Joseph · Updated
A power cut mid-save, an email garbled in transit, a download that never quite completes. How data gets corrupted and what it does to security.
Read More
Cost Benefit Analysis: How Important Is Cost Benefit Analysis in Cybersecurity Investments?
By Charles Joseph · Updated
Expanding a business, building a transit line, buying software: the math is the same. How a cost-benefit analysis works, and why security budgets need it.
Read More
Countermeasure: What Makes a Countermeasure Effective?
By Charles Joseph · Updated
A firewall, an update, encryption. Each is a countermeasure against a specific threat. What makes one effective, and when it isn't enough.
Read More
Chain of Custody: Why Is Chain of Custody Crucial in Digital Forensics?
By Charles Joseph · Updated
Evidence is only as good as the record of who touched it. Why the chain of custody matters at crime scenes, in medical labs and in digital forensics.
Read More
CGI: How Does CGI Impact Web Security?
By Charles Joseph · Updated
Forms, comment sections and dynamic pages all needed a way to talk to the server. What CGI does, and the security questions that come with it.
Read More
Certificate-Based Authentication: How Secure Is Certificate-Based Authentication?
By Charles Joseph · Updated
A digital certificate is like an ID card a trusted authority has stamped. How it secures email, websites and VPNs, and how it compares to a password.
Read More
Bridge: How Does a Bridge Enhance Network Functionality?
By Charles Joseph · Updated
Two networks become one, and traffic flows where it should. How a bridge works in your home, your office and at the ISP.
Read More
British Standard 7799: How Influential Is British Standard 7799?
By Charles Joseph · Updated
A British guide to managing information security that shaped how companies think about risk, physical security and continuity. What BS 7799 asked for, and why it mattered.
Read More
Broadcast: How Do Broadcasts Impact Network Traffic?
By Charles Joseph · Updated
Radio, television and your Wi-Fi router all do it: one sender, everyone listening. How broadcasting works on a network and what it does to traffic.
Read More
Broadcast Address: What Is the Role of a Broadcast Address?
By Charles Joseph · Updated
One address reaches every machine on the network at once. How broadcast addresses handle updates, discovery and DHCP requests.
Read More
Business Continuity Plan (BCP): Why Is a BCP Essential?
By Charles Joseph · Updated
A retailer's backup inventory, a media company's data copies, a hospital's generator. What a continuity plan covers, and why every organization needs one.
Read More
Byte: Why Is Byte Important in Digital Communication?
By Charles Joseph · Updated
Eight bits, one character, every keystroke you've ever typed. What a byte is and why the unit shows up everywhere in digital communication.
Read More
Brute Force: How Effective Is Brute Force Against Modern Encryption?
By Charles Joseph · Updated
No cleverness, just every combination until one works. How brute force cracks passwords, PINs and files, and whether modern encryption can outlast it.
Read More
Cache: How Can Cache Pose Security Threats?
By Charles Joseph · Updated
Your browser, your processor and your image viewer all keep copies for speed. How caches work, and the ways that stored data can be turned against you.
Read More
Cache Cramming: How Prevalent Is Cache Cramming?
By Charles Joseph · Updated
A malicious script slips into your browser's cache and waits. How cache cramming works, and how common the trick really is.
Read More
Cache Poisoning: How Is Cache Poisoning Executed?
By Charles Joseph · Updated
You type your bank's address correctly and still land on a fake site. How attackers corrupt DNS caches, with three ways it plays out.
Read More
Call Admission Control (CAC): How Does CAC Maintain Quality of Service?
By Charles Joseph · Updated
Too many calls on one network and everyone sounds terrible. How CAC decides who gets through, in phone systems, video meetings and streaming.
Read More
Cell: What Is the Role of Cells in Networks?
By Charles Joseph · Updated
Hackers, like other groups, organize into small units that share tools and goals. What a cell looks like in cybercrime, with three examples.
Read More
Bastion Host: What Makes a Bastion Host Secure?
By Charles Joseph · Updated
A single hardened machine stands between your network and the open internet. What a bastion host runs, what it refuses, and why it's built to take the hits.
Read More
BIND: What Role Does BIND Play in DNS?
By Charles Joseph · Updated
Type a web address and something has to turn it into a number. BIND has done that job for much of the internet. How it works and where it fits in DNS.
Read More
Biometrics: How Reliable Are Biometric Systems?
By Charles Joseph · Updated
Fingerprints, faces, voices: things you can't forget or leave at home. How biometric systems verify you, and how far they can be trusted.
Read More
Bit: How Is a Bit Significant in Cybersecurity?
By Charles Joseph · Updated
Everything on a computer comes down to zeros and ones. What a bit is, where you meet it, and why the smallest unit matters in security.
Read More
Boot Record Infector: How Does a Boot Record Infector Operate?
By Charles Joseph · Updated
It loads before your operating system does, which makes it hard to see and harder to remove. How a boot record infector works, and the signs you have one.
Read More
Border Gateway Protocol (BGP): What Risks Exist in BGP?
By Charles Joseph · Updated
It's the GPS for internet traffic, steering your email across continents and your video across the globe. What BGP does, and what goes wrong when it's abused.
Read More
Access Matrix: What Purpose Does It Serve?
By Charles Joseph · Updated
A table of who can do what to which resource sounds dull until it's the only thing stopping a leak. How an access matrix works, from banking to social media.
Read More
Basic Authentication: Is Basic Authentication Still Reliable?
By Charles Joseph · Updated
A username and password sent the simple way. Where basic authentication still shows up, and why that simplicity is also the problem.
Read More
Banner: What Information Does a Banner Reveal?
By Charles Joseph · Updated
When a server says hello, it often says too much. What a banner reveals about the software behind it, and why attackers read them first.
Read More
Bandwidth: Can Bandwidth Affect Cybersecurity?
By Charles Joseph · Updated
The size of the pipe decides how fast your video loads and your game responds. What bandwidth is, and the ways it can turn into a security concern.
Read More
What Is Access Management Access?
By Charles Joseph · Updated
Large companies, social apps and online banks all have to decide who sees what. How access management handles that, with examples from each.
Read More
ACK Piggybacking: How Is ACK Piggybacking Utilized?
By Charles Joseph · Updated
Networks save effort by letting an acknowledgment hitch a ride on real data. How piggybacking works in email, downloads and online games.
Read More
Activity Monitors: Are Activity Monitors Invasive or Necessary?
By Charles Joseph · Updated
Parents use them, companies use them, and some people run them on themselves. What activity monitors record, and the line between care and surveillance.
Read More
Address Resolution Protocol (ARP): How Does ARP Benefit Network Communication?
By Charles Joseph · Updated
Your computer knows an IP address but needs a hardware one. ARP makes the match, on your home Wi-Fi and in the office, usually without you noticing.
Read More
Algorithm: How Reliable Are Cybersecurity Algorithms?
By Charles Joseph · Updated
A recipe for a computer, from search rankings to sorting lists. What an algorithm is, where you meet them every day and how much trust they deserve.
Read More
Applet: What Security Concerns Surround Applets?
By Charles Joseph · Updated
Small programs that run inside a bigger one: online games, weather widgets, chat windows. What applets do, and why security people kept a wary eye on them.
Read More
Autonomous System: What Role Does an Autonomous System Play?
By Charles Joseph · Updated
The internet is a city of districts, each with its own traffic rules. What an autonomous system is, and why ISPs, universities and big companies run their own.
Read More
What Is an Access Control Service?
By Charles Joseph · Updated
Someone has to decide who can open which doors, digital or physical. How an access control service manages that, from company systems to cloud storage.
Read More
Asymmetric Warfare: How Does Asymmetric Warfare Impact Cybersecurity?
By Charles Joseph · Published
Guerrillas, terrorists and hackers all fight the same way: find the big opponent's soft spot. How the oldest idea in warfare plays out online.
Read More
Triple DES: Is Triple DES Still Secure?
By Charles Joseph · Published
Encrypt, decrypt, encrypt again with three keys. How Triple DES works for banking, email and e-commerce, and whether it's still secure.
Read More
TELNET: Why Should TELNET Be Avoided?
By Charles Joseph · Published
Text-based remote access with no encryption at all. What Telnet does for admins, and why it should be avoided.
Read More
Standard ACLs (Cisco): How to Implement Standard ACLs in Cisco?
By Charles Joseph · Published
Allow or deny by source address alone. How standard ACLs protect data, control traffic and separate guest from office networks.
Read More
T1: What Is a T1 Line in Networking?
By Charles Joseph · Published
1.544 megabits per second, from telephone lines to business internet. What a T1 line is, and who still uses one.
Read More
Shell: How Secure Is Your Shell?
By Charles Joseph · Published
List files, rename in bulk, watch processes. What a shell does, and how secure yours is.
Read More
Software: What Makes a Software Secure?
By Charles Joseph · Published
Windows, Chrome and Photoshop are all instructions written for a machine. What software is, and what makes it secure.
Read More
Secure Electronic Transactions (SET): How Safe Are SET Transactions?
By Charles Joseph · Published
Keep card details hidden from the merchant. How SET protects shopping, flight booking and subscriptions, and how safe it is.
Read More
Public-Key Forward Secrecy (PFS): How Does It Enhance Communication Security?
By Charles Joseph · Published
Breaking one message doesn't break the rest. How forward secrecy works, explained with lockboxes, postcards and unique passwords.
Read More
Protocol: Why Is It Crucial for Network Communications?
By Charles Joseph · Published
HTTP, SMTP and FTP are the languages devices speak to each other. What a protocol is, and why nothing communicates without one.
Read More
Poison Reverse: How Does It Prevent Routing Loops?
By Charles Joseph · Published
Tell every router that the way back is closed. How poison reverse prevents routing loops, explained with roundabouts and hot potatoes.
Read More
Input Validation Attacks: How to Prevent Them?
By Charles Joseph · Published
SQL injection, cross-site scripting and command injection all start with input nobody checked. How the attacks work, and how to shut them out.
Read More
Loadable Kernel Modules (LKM): What Are They Used For?
By Charles Joseph · Published
Device drivers, filesystems and network protocols added to a running kernel without a reboot. What LKMs are for, and what that access means.
Read More
Issue-Specific Policy: Why Is It Necessary?
By Charles Joseph · Published
Email use, social media, data handling. Why narrow policies matter, with examples of each.
Read More
Incident Handling: How Effective Can It Be?
By Charles Joseph · Published
Prepare, identify, contain, eradicate, recover, review. How incident handling works for phishing, malware and DDoS, and how well it holds up.
Read More
Forest: How Does Forest Structure Influence Active Directory?
By Charles Joseph · Published
In Active Directory, domains grow into trees and trees into forests. How a multinational uses a forest to manage its branches.
Read More
Hijack Attack: How Damaging Can a Hijack Attack Be?
By Charles Joseph · Published
Your browser redirects, your session is intercepted, your email account answers to someone else. How hijack attacks work and how much they can take.
Read More
DumpSec: What Information Can DumpSec Reveal?
By Charles Joseph · Published
User accounts, permissions and policies, pulled from Windows into one readable report. What DumpSec reveals, and who uses it.
Read More
Domain: How Does a Domain Relate to Cybersecurity?
By Charles Joseph · Published
google.com, amazon.com, facebook.com: addresses you type without thinking. What a domain is, and why it matters to security.
Read More
Day Zero: How Damaging Can a Day Zero Attack Be?
By Charles Joseph · Published
The flaw is public, the patch doesn't exist yet, and attackers know it. What day zero means, and how much damage can be done in that window.
Read More
Configuration Management: How Does Configuration Management Improve Security?
By Charles Joseph · Published
Every change to a system should be recorded, approved and tracked. How configuration management works for developers, web services and IT teams, and why it cuts risk.
Read More
Business Impact Analysis (BIA): How Does BIA Contribute to Risk Management?
By Charles Joseph · Published
Before you can plan for a disaster, you need to know what it would cost. How a business impact analysis finds the operations you can't afford to lose.
Read More
Account Harvesting: What Drives These Attacks?
By Charles Joseph · Published
Usernames and passwords are collected in bulk, by phishing, keyloggers and breaches. What attackers do with the harvest and why your login is worth taking.
Read More
Access Control List (ACL): How Effective Is It?
By Charles Joseph · Published
A list of rules decides which traffic may pass and which gets turned away. How ACLs guard internal servers, school networks and company apps.
Read More
Windump: How to Use Windump for Network Analysis?
By Charles Joseph · Updated
tcpdump for Windows. How Windump captures packets for monitoring, troubleshooting and intrusion detection.
Read More
Voice Intrusion Prevention System (IPS): How Effective Is Voice IPS?
By Charles Joseph · Updated
Call centers, corporate offices and telecom providers watching voice traffic for threats. How voice IPS works, and how effective it is.
Read More
Wireless Application Protocol: How Secure Is WAP?
By Charles Joseph · Published
The bridge that brought the web to early mobile phones. What WAP did for browsing and email, and how secure it was.
Read More
Windowing: How Does Windowing Enhance Network Efficiency?
By Charles Joseph · Published
Data sent in chunks sized to what the receiver can handle. How windowing speeds up streaming, file transfers and databases.
Read More
Web of Trust: How Effective Is a Web of Trust?
By Charles Joseph · Published
Green for safe, yellow for doubtful, red for stay away. How the Web of Trust rates websites, and how effective crowd ratings are.
Read More
War Dialer: How Dangerous Is a War Dialer?
By Charles Joseph · Published
A program that dials every number in a range, hunting for modems that answer. How war dialers work, and how dangerous they are.
Read More
War Chalking: What Is War Chalking and Why Is It a Threat?
By Charles Joseph · Published
Chalk symbols on a wall told strangers where the open Wi-Fi was. What war chalking was, and why it was a threat.
Read More
Trusted Ports: What Are Trusted Ports in Firewalls?
By Charles Joseph · Published
SSH, HTTPS and SMTP ride on ports deemed safe. What trusted ports are, and how firewalls treat them.
Read More
Tunnel: How Secure Is VPN Tunneling?
By Charles Joseph · Published
A private path through public Wi-Fi, from the coffee shop to the office. How tunneling works, and how secure VPN tunnels are.
Read More
UDP Scan: What Is the Purpose of a UDP Scan?
By Charles Joseph · Published
Send UDP packets, watch the responses, find the open ports. What a UDP scan is for, with examples.
Read More
Unicast: What Is Unicast Communication?
By Charles Joseph · Published
One sender, one receiver. How unicast works for email, video on demand and phone calls.
Read More
Uniform Resource Identifier (URI): What Is the Role of URI in Networking?
By Charles Joseph · Published
URLs and URNs are both URIs. What a uniform resource identifier is, and its role in networking.
Read More
Uniform Resource Locator (URL): How to Securely Use URLs?
By Charles Joseph · Published
Protocol, domain, path. What a URL is, and how to use them securely.
Read More
Unix: How Secure Is Unix?
By Charles Joseph · Published
Corporations, web developers and mobile devices all run on it. What Unix is, and how secure it really is.
Read More
Buffer Overflow: How Damaging Are They?
By Charles Joseph · Updated
A form field, a username box, an email client: give any of them more than they expected and strange things happen. How buffer overflows work, and how much damage they do.
Read More
Data Encryption Standard (DES): How Secure Is Data Encryption Standard?
By Charles Joseph · Updated
The 1970s cipher that secured banking and email for decades. How DES works, and how its security holds up today.
Read More
Auditing: Why Is Auditing Vital for Cybersecurity?
By Charles Joseph · Updated
Financial books, school safety, restaurant kitchens: the audit is how you find out if things are really as they should be. Why security needs the same habit.
Read More
Advanced Encryption Standard (AES): Why Choose It?
By Charles Joseph · Updated
It protects your files, your email and your Wi-Fi, and NIST chose it for a reason. What AES does and why it became the standard the world settled on.
Read More
Sniffing: How to Defend Against Sniffing Attacks?
By Charles Joseph · Updated
Unencrypted data on the network is readable to anyone listening. How sniffing is used for debugging, monitoring and stealing, and how to defend against it.
Read More
ARPANET: How Did ARPANET Shape Today’s Internet?
By Charles Joseph · Updated
The Pentagon's 1960s research network gave us email, TCP/IP and the idea of a global network. How ARPANET became the internet.
Read More
Password Sniffing: How Can It Be Prevented?
By Charles Joseph · Updated
Software that watches the network and records passwords as they pass. How password sniffing works, and how to prevent it.
Read More
Smurf: How to Counter a Smurf Attack?
By Charles Joseph · Updated
Bounce traffic off a whole network and aim it at one victim. How Smurf attacks crash business, e-commerce and government sites, and how to counter them.
Read More
Subnet Mask: How to Determine the Correct Subnet Mask?
By Charles Joseph · Updated
255.255.255.0 and what it means for your addresses. How subnet masks work in offices, universities and homes.
Read More
Zombies: What Are Zombie Computers and How to Prevent Them?
By Charles Joseph · Updated
One dubious attachment and your computer joins an army. What zombie computers are, how they're recruited, and how to prevent it.
Read More
SHA1: Is SHA1 Still Considered Secure?
By Charles Joseph · Updated
Git, password storage and document verification still lean on it, and experts have moved on. What SHA1 does, and whether it's still safe.
Read More
Sub-Network: Why Is Subnetting Necessary?
By Charles Joseph · Updated
Split a network into smaller ones and everything gets faster and safer. Why subnetting is necessary, with examples.
Read More
War Dialing: Is It Still Relevant Today?
By Charles Joseph · Updated
Dial a thousand numbers and wait for a modem to pick up. How war dialing worked, and whether it still matters.
Read More
What Is a Computer User?
By Charles Joseph · Updated
Anyone who interacts with a system, from a guest to an administrator. What a user is, and why access levels matter.
Read More
Threat Vector: How to Identify Threat Vectors?
By Charles Joseph · Updated
Phishing emails, malicious websites, unsecured networks. What a threat vector is, and how to identify them.
Read More
What Is an Indicator of Compromise (IOC)?
By Charles Joseph · Updated
Criminals leave fingerprints; hackers leave IOCs. The most common types, how they're found and used, and where the idea came from.
Read More
What Is Cross-Site Scripting (XSS)?
By Charles Joseph · Updated
Stored, reflected and DOM-based. How XSS injects scripts into pages other people view, the defenses, and real-world cases.
Read More
What Is DDoS?
By Charles Joseph · Updated
Thousands of machines hit one target until it falls over. The key takeaways on distributed denial of service, and why it's so hard to stop.
Read More
Exploit: How Fast Can It Spread?
By Charles Joseph · Updated
Browser, email and mobile app exploits turn a bug into a break-in. How exploits work, how fast they spread, and the famous ones worth knowing.
Read More
What Are Tactics, Techniques, and Procedures (TTPs)?
By Charles Joseph · Updated
Get inside the attacker's head by breaking down their behavior. What TTPs are, how they're used, and the history and numbers behind them.
Read More
What Is a Social Engineering Attack?
By Charles Joseph · Updated
The technical defenses got better, so the attackers turned to people. The types, history and famous cases of social engineering.
Read More
What Is a Computer Virus?
By Charles Joseph · Updated
Not every piece of malware is a virus. What viruses are, how they work, their history, the numbers and the famous ones.
Read More
What Is a Computer Worm?
By Charles Joseph · Updated
Fifty years of self-spreading malware, billions in damage. What worms are, how they spread, their history and the numbers.
Read More
Trojan Horse: Can It Be Detected before It’s Too Late?
By Charles Joseph · Updated
A gift that turns out to be an army. How trojans spread, the types and what they do, and whether they can be caught in time.
Read More
Concealed & Dangerous: Unveil the Truth About Rootkits
By Charles Joseph · Updated
Malware that hides itself and hands an attacker full control. How rootkits spread, what they can do, and the history behind them.
Read More
The Danger of Fileless Malware: Are You at Risk?
By Charles Joseph · Updated
No file to scan, nothing to delete. How fileless malware gets in, stays hidden and does its work, and whether you're at risk.
Read More
Learn What Adware Is Before It Destroys Your Computer
By Charles Joseph · Updated
Nobody loves ads, but adware is something else entirely. How it gets in, what it does to your machine and the history and numbers behind it.
Read More
What Is a Backdoor?
By Charles Joseph · Updated
A hidden door into a system, sometimes built by the developers themselves. Five kinds of backdoor, and why the secret entrance never stays secret.
Read More
What Is AES?
By Charles Joseph · Updated
Symmetric, block-based and chosen by NIST in 2001. A short tour of the encryption standard that quietly protects most of what you do online.
Read More
What Is an OUI? (And Its History)
By Charles Joseph · Updated
The first 24 bits of every MAC address name the manufacturer. Where OUIs came from, who assigns them and how many are left.
Read More
What Is a Whitelist?
By Charles Joseph · Updated
Only the approved get in. The key points on whitelists, and five reasons to use one.
Read More
What Is Wi-Fi?
By Charles Joseph · Updated
Radio waves instead of cables, at home, at work and in the coffee shop. The key points on Wi-Fi, and five reasons to use it.
Read More
What Is a Vulnerability Scan?
By Charles Joseph · Updated
Look for known weaknesses before someone else does. The key points on vulnerability scans, and five reasons to run one.
Read More
What Is a YARA Rule?
By Charles Joseph · Updated
Strings plus a Boolean expression equals a malware detector. What YARA rules are, how to use them, and five reasons researchers rely on them.
Read More
What Is Vishing?
By Charles Joseph · Updated
Phishing by phone, with a spoofed caller ID. The key points on vishing, and five reasons hackers use it.
Read More
What Is a Drive-by Download?
By Charles Joseph · Updated
Visit the wrong page and malware installs itself, no click required. The key points on drive-by downloads, and five reasons hackers love them.
Read More
What Is a SaaS?
By Charles Joseph · Updated
Software you access through a browser, with the provider managing everything behind it. The key points on SaaS.
Read More
What Is Cyber Espionage?
By Charles Joseph · Updated
Spies no longer need to break into a building. The key points on cyber espionage, and five reasons it happens.
Read More
What Is Pen Testing? (Hacking for Good)
By Charles Joseph · Updated
Spies, secret codes and high-tech heists, without leaving your chair. What pen testing is, the types, and why it's hacking for good.
Read More
What Is Two-Factor Authentication?
By Charles Joseph · Updated
A password plus a code on your phone. The key points on two-factor authentication.
Read More
IDS: Is It Essential for Network Security?
By Charles Joseph · Updated
A burglar alarm for your network, watching while you're not. What an intrusion detection system does, the popular ones, and whether you can do without.
Read More
What Is an IPS?
By Charles Joseph · Updated
Detect the attack and stop it in the same motion. The key points on intrusion prevention systems.
Read More
What Is Social Engineering?
By Charles Joseph · Updated
Hack the person, not the machine. The key points on social engineering.
Read More
Spear Phishing: the Most Terrifying Cyber-Attack
By Charles Joseph · Updated
Not a wide net but a single, carefully aimed message. How spear phishing works, a scenario from a town government, and its history.
Read More
What Is Packet Sniffing?
By Charles Joseph · Updated
Watch the data as it crosses the network. The key points on packet sniffing, for troubleshooting and for theft.
Read More
What Is a Honeypot?
By Charles Joseph · Updated
A decoy built to attract hackers and study their moves. The key points on honeypots.
Read More
What Is IaaS?
By Charles Joseph · Updated
Rent the servers, storage and networking instead of buying them. The key points on infrastructure as a service, and what you still have to secure yourself.
Read More
SIEM: What Is It?
By Charles Joseph · Updated
Logs from everywhere, analyzed in one place. The key points on security information and event management, with a video explainer.
Read More
What Is an Encryption Key?
By Charles Joseph · Updated
Key types, key lengths, rotation and exchange. The short guide to the string of characters that stands between your data and everyone else.
Read More
What Is Two-Step Authentication?
By Charles Joseph · Updated
Username, password, then a code by text. The key points on two-step authentication.
Read More
What Is a Security Control?
By Charles Joseph · Updated
Locks and fences, passwords and firewalls. The key points on physical, technical and administrative controls.
Read More
What Is Patch Management?
By Charles Joseph · Updated
Identify, acquire, install, verify. The key points on patch management, and why timing matters.
Read More
What Are Common Vulnerabilities and Exposures (CVE)?
By Charles Joseph · Updated
Every publicly known security flaw gets a number. Who assigns CVEs, and why the list matters to anyone defending a system.
Read More
What Is Patching? And When Should You Do It?
By Charles Joseph · Updated
Security fixes, bug fixes, new features. What a patch does, how often to apply them, and what to do before you click update.
Read More
What Is Sandboxing?
By Charles Joseph · Updated
Run untrusted code in a box where it can't hurt anything. The key points on sandboxing.
Read More
What Is a DMZ?
By Charles Joseph · Updated
A buffer network between your systems and the internet. The key points on how a DMZ keeps exposed servers from exposing everything else.
Read More
What Is Link Jacking?
By Charles Joseph · Updated
The link looks real, the site looks real, and your information is gone. The key points on link jacking.
Read More
What Is a Payment Card Skimmer?
By Charles Joseph · Updated
A device on the ATM or gas pump reads your card before the bank does. The key points on skimmers.
Read More
What Is Identity Fraud?
By Charles Joseph · Updated
Someone else's name, your money gone. The key points on identity fraud, and the ways it's committed.
Read More
What Is BCP?
By Charles Joseph · Updated
Disaster will strike eventually. A business continuity plan decides whether it's a bad week or the end. The elements every plan needs.
Read More
What Is BYOD?
By Charles Joseph · Updated
Employees bring their own phones and laptops to work, and the company gets productivity and a security headache in one package. The key points on BYOD.
Read More
What Is SCADA?
By Charles Joseph · Updated
The industrial control systems behind power grids and water systems. What SCADA is, and why hackers target it.
Read More
What Is a Blacklist?
By Charles Joseph · Updated
Known spammers, bad IP addresses, banned software. A blacklist is the simplest defense there is. Where it's used and where it falls short.
Read More
What Is Hacktivism?
By Charles Joseph · Updated
Defaced sites, blocked services and leaks, all in the name of a cause. The key points on hacktivism.
Read More
What Is a Hub?
By Charles Joseph · Updated
Cheap, simple and old-fashioned. What a hub does on a LAN, and the pros and cons of using one.
Read More
What Is NVRAM?
By Charles Joseph · Updated
Memory that keeps its data when the power goes off. What NVRAM is, and where it's used.
Read More
What Is the Cisco Discovery Protocol (CDP) and Why Use It
By Charles Joseph · Updated
Cisco gear quietly introduces itself to its neighbors. What CDP shares, why admins find it handy, and what to keep in mind.
Read More
What Is LLDP?
By Charles Joseph · Updated
Network devices announcing themselves to their neighbors, vendor-neutral. What LLDP does, and the benefits for visibility, troubleshooting and security.
Read More
What Is ARM?
By Charles Joseph · Updated
The chip architecture in your phone, your tablet and probably your TV. What ARM is, why it took over, and where it's heading next.
Read More
What Is UEFI?
By Charles Joseph · Updated
The modern replacement for BIOS, with Secure Boot built in. What UEFI is, and how it compares.
Read More
What Is a CPU Core?
By Charles Joseph · Updated
Two cores, four, sixteen: the number on the box matters more than you'd think. What a core does, and how to pick the right count for your needs.
Read More
What Is CISC?
By Charles Joseph · Updated
Complex instruction sets power most desktops and laptops. Where CISC came from, how it compares to the alternative, and the processors that use it.
Read More
What Are Kernel Capabilities? (35 Listed)
By Charles Joseph · Updated
Root power, split into 35 separate pieces. How Linux kernel capabilities let a process do one privileged thing without being able to do everything.
Read More
What Is the Cyber Kill Chain?
By Charles Joseph · Updated
Seven phases, from reconnaissance to action. Lockheed Martin's model for how an attack unfolds, in brief.
Read More
What Is a Script Kiddie?
By Charles Joseph · Updated
Pre-written tools, no real understanding. What a script kiddie is, and where the term came from.
Read More
What Is an RCE? (and 9 Reasons Hackers Use Them)
By Charles Joseph · Updated
Run code on someone else's machine from anywhere. What remote code execution is, nine reasons hackers love it, and six examples.
Read More
What Is Firmware?
By Charles Joseph · Updated
The software baked into your router, camera and phone. What firmware does, and why it sits between hardware and everything else.
Read More
RISC: The Key to Your Smartphone’s Speed
By Charles Joseph · Updated
The reduced instruction set behind your smartphone's speed. What RISC is, how it differs from CISC, and where it's headed.
Read More
What Is a Next-Generation Firewall?
By Charles Joseph · Updated
Deep packet inspection and application-level control, on top of the traditional firewall. What makes an NGFW different, in plain English.
Read More
What Is a CWE?
By Charles Joseph · Updated
Before a vulnerability exists, there's a weakness that allowed it. What the Common Weakness Enumeration lists, and how it helps.
Read More
What Is an Advanced Persistent Threat (APT)?
By Charles Joseph · Updated
Some attacks are a blitz. These are a siege, lasting weeks, months or years. The five stages of an APT, who runs them, and the history behind the term.
Read More
What Is Network Segmentation?
By Charles Joseph · Updated
Divide the network into isolated pieces, and a breach in one stays in one. The short version of network segmentation.
Read More
What Is a Deepfake?
By Charles Joseph · Updated
Faces that never said those words, voices that never spoke them. The five steps that turn a pile of photos into a convincing fake.
Read More
What Is Perfect Forward Secrecy (PFS) and How Does It Work?
By Charles Joseph · Updated
A new key for every session, so one stolen key doesn't unlock the past. How perfect forward secrecy works, with a decoder-ring analogy.
Read More
What Is IPSec?
By Charles Joseph · Updated
A digital shield for data on the move, from home office to corporate VPN. How IPsec works, with AH and ESP in transport mode.
Read More
Memory Forensics: Decoding Digital Mysteries
By Charles Joseph · Updated
Running processes, open connections and credentials, all still in RAM. How memory forensics reads what a computer was doing at the moment it was caught.
Read More
HTTP: Unlock the Language of the Internet
By Charles Joseph · Updated
Every page you load starts with a request. What HTTP is, what goes into a request and a response, and the headers that make it all work.
Read More
What Is Zero Trust?
By Charles Joseph · Updated
Never trust, always verify, inside the network as much as outside. What zero trust is, and the steps to implement it.
Read More
What Is LTE?
By Charles Joseph · Updated
The 4G standard behind fast mobile data. What LTE is, how it improved on 3G, and the features that made it the norm.
Read More
What Is SD-WAN? (And 5 Reasons to Use It)
By Charles Joseph · Updated
A software-defined approach to connecting a company's locations. What SD-WAN is, and five reasons businesses use it.
Read More
Watering Hole Attack: What Is It Exactly?
By Charles Joseph · Updated
Predators wait where the prey will come to drink. How hackers do the same with websites, famous cases, and how to avoid the trap.
Read More
Access: What Dangers Lurk?
By Charles Joseph · Updated
Logging into your email is access. So is a stranger reaching a company database. Why such a simple word carries so much weight in security.
Read More
Access and Identity Management: Friend or Foe?
By Charles Joseph · Updated
Proving who you are and getting only what you need, from an office login to your bank app. How identity management works, and where it can get in your way.
Read More
Access Control: How Effective Can It Be?
By Charles Joseph · Updated
A gated community and a company database rely on the same idea: not everyone gets in. How access control works, and the limits of the lock.
Read More
Access Control Mechanism: Where Can It Fail?
By Charles Joseph · Updated
Passwords, fingerprints and smart cards all answer one question: should this person get in? The mechanisms behind that question, and their weak spots.
Read More
Active Attack: How Quickly Can It Spread?
By Charles Joseph · Updated
Some attackers listen. Others change things. What an active attack looks like on a website or in your inbox, and why it's the kind you notice too late.
Read More
Active Content: A Hidden Danger in Websites?
By Charles Joseph · Updated
Animations, forms and live updates make a site feel alive. The same scripts can open a door. Where active content helps and where it hurts.
Read More
Adversary: Who Could Be the Silent Intruder?
By Charles Joseph · Updated
Rival companies, hackers, activist groups: the threat doesn't always look like a hoodie in a basement. Who counts as an adversary, with examples.
Read More
Air Gap: The Ultimate Cybersecurity Solution?
By Charles Joseph · Updated
Unplug a system from every network and it should be untouchable. Militaries, banks and factories rely on the idea. Whether it holds up is the question.
Read More
Alert: Is Ignoring It an Invitation to Disaster?
By Charles Joseph · Updated
Failed logins, antivirus warnings, odd spending on your card. Alerts are easy to dismiss. What they're trying to tell you, and when to act on one.
Read More
Allowlist: How Can It Enhance Cybersecurity?
By Charles Joseph · Updated
Instead of blocking the bad, you name the good and refuse everything else. How allowlists work for email, software and network access.
Read More
All Source Intelligence: A Panacea for Cyber Threats?
By Charles Joseph · Updated
Human sources, signals, open data: combine them and a clearer picture emerges. How all-source intelligence works for businesses, disaster teams and researchers.
Read More
Analyze: The Cornerstone of Cyber Defense?
By Charles Joseph · Updated
Test results, sales figures, a food diary. Breaking something down to understand it is the skill underneath every good decision in security.
Read More
Antispyware Software: An Effective Countermeasure or Not?
By Charles Joseph · Updated
Programs that quietly collect your information need a program that quietly hunts them. What antispyware does, three examples, and how much to expect from it.
Read More
Antivirus Software: Is It Enough for Cyber Protection?
By Charles Joseph · Updated
Norton, McAfee, Bitdefender and the rest promise to keep malware out. How antivirus actually works, and whether it's enough on its own.
Read More
Asset: What Could Be the Biggest Cybersecurity Target?
By Charles Joseph · Updated
A laptop, a piece of software, a customer database, even a person. What counts as an asset, and which ones attackers prize most.
Read More
Asymmetric Cryptography: Is It the Future of Cybersecurity?
By Charles Joseph · Updated
One key you share with the world, one you guard with your life. How the pair secures email, websites and digital signatures, and where it goes from here.
Read More
Attack: How Can We Predict Its Trajectory?
By Charles Joseph · Updated
Phishing, malware, denial of service. Every attack is an attempt to break, steal or sneak in. How the common ones unfold, and whether you can see them coming.
Read More
Attack Method: What’s the Most Prevalent Trend?
By Charles Joseph · Updated
Trick someone into typing a password, or guess it a million times. Why hackers choose one method over another, and which one keeps winning.
Read More
Attack Mode: How Does It Determine Impact Severity?
By Charles Joseph · Updated
The same hacker can phish, drop malware or flood a server. How the chosen mode shapes the damage, with three examples.
Read More
Attack Path: Can We Map It Accurately?
By Charles Joseph · Updated
Every breach is a route: an email here, a weak server there. How mapping the attacker's path turns a vague threat into something you can block.
Read More
Attack Pattern: Can Predictive Analysis Be a Game Changer?
By Charles Joseph · Updated
Attackers repeat themselves more than they'd like to admit. How recognizing the pattern behind phishing, brute force and SQL injection lets defenders get ahead.
Read More
Attack Signature: How Is It a Cyber Defense Key?
By Charles Joseph · Updated
Ten failed logins in a minute. A suspicious burst of email. Traffic that looks wrong. How security tools recognize an attack by its fingerprint.
Read More
Attack Surface: How Can We Minimize It?
By Charles Joseph · Updated
Open ports, unpatched software, that one app nobody approved. Every exposed point is an invitation. How to count them and how to shrink the list.
Read More
Attacker: Can We Identify Them before the Attack?
By Charles Joseph · Updated
Scammers, virus writers and website defacers rarely announce themselves. What attackers have in common, and whether they can be spotted first.
Read More
Authenticate: How Crucial Is It for Data Protection?
By Charles Joseph · Updated
Your email login, your fingerprint, your bank's extra check. Why proving who you are is the first line of defense for everything behind it.
Read More
Authentication: Does It Always Ensure Security?
By Charles Joseph · Updated
A password, a fingerprint, a smart card. Each proves identity in its own way. How authentication works, and the ways it can still let you down.
Read More
Authenticity: Can It Be Falsified in Cyberspace?
By Charles Joseph · Updated
Is that website, that email, that signature really what it claims to be? The tools that vouch for authenticity online, and how convincing a fake can get.
Read More
Authorization: How Does It Limit Cybersecurity Breaches?
By Charles Joseph · Updated
Logging in gets you through the door. Authorization decides which rooms you may enter. How it works in banking, social media and the HR system.
Read More
Availability: Does It Pose a Cybersecurity Paradox?
By Charles Joseph · Updated
A website that's down is a website that's useless. Why keeping systems reachable is as much a security goal as keeping them locked, and the trade-offs involved.
Read More
Advanced Persistent Threat: How Do We Combat This Menace?
By Charles Joseph · Updated
They don't smash and grab. They move in and stay, sometimes for years. What makes an APT different, who gets targeted, and how defenders fight back.
Read More
Behavior Monitoring: Can It Predict Cyber Attacks?
By Charles Joseph · Updated
A login at 3 a.m., a sudden interest in sensitive files, odd browsing. How watching for unusual behavior catches threats before the damage is done.
Read More
Blocklist: How Effective Is It in Cybersecurity?
By Charles Joseph · Updated
Email addresses, websites and IPs that have earned a place on the wrong list. How blocklists work, and the limits of keeping the bad guys out by name.
Read More
Blue Team: The Unsung Heroes of Cybersecurity?
By Charles Joseph · Updated
While red teams get the glory, someone has to watch the network every day. What the blue team does, and why defense is the harder job.
Read More
Bot: Is It the Cybercriminal’s Best Friend?
By Charles Joseph · Updated
Chatbots help, social bots mislead, spam bots flood. What a bot is, how it's used for good and bad, and why criminals love automation.
Read More
Bot Herder: The Puppet Master behind Cybercrime?
By Charles Joseph · Updated
Alice's computer, Ben's security camera and Charlie's new app all answer to someone else. How a bot herder builds an army out of ordinary devices.
Read More
Bot Master: Can We Crack Down on Them?
By Charles Joseph · Updated
Thousands of infected machines, one person pulling the strings. What a bot master does with the network, and what it takes to stop one.
Read More
Botnet: How Big of a Threat Is It?
By Charles Joseph · Updated
Your computer might be part of an army without you knowing. How botnets are built, what they're used for and how big the threat really is.
Read More
Bug: Is It the Weakest Link in Cybersecurity?
By Charles Joseph · Updated
A crash, a wrong price, a privacy glitch. Every bug is a small failure, and some are an open door. Why flaws in code are often the weakest link.
Read More
Build Security In: Can It Outsmart Cybercriminals?
By Charles Joseph · Updated
Bolting security on at the end never works as well as building it in from the first line. What the approach involves, and whether it can outsmart attackers.
Read More
Capability: How Does It Define a Cyber Attacker?
By Charles Joseph · Updated
A developer who knows Python, a phone that shoots video, a designer with the right tools. What capability means, and how it defines what an attacker can do.
Read More
Cipher: Can It Ensure Absolute Data Security?
By Charles Joseph · Updated
Caesar shifted letters, Atbash flipped the alphabet, and transposition scrambled the order. What a cipher is, and whether any can promise absolute secrecy.
Read More
Ciphertext: How Unbreakable Can It Be?
By Charles Joseph · Updated
What your message looks like after encryption: gibberish to everyone but the right reader. How ciphertext works, and how unbreakable it can get.
Read More
Cloud Computing: A Boon or Bane for Cybersecurity?
By Charles Joseph · Updated
Gmail, Dropbox and Netflix live on someone else's servers. What cloud computing is, and whether handing over your data makes you safer or more exposed.
Read More
Collect and Operate: How Does It Aid Cyber Defense?
By Charles Joseph · Updated
A retailer, a basketball team and a health app all gather data and act on it. How collect and operate works, and what it means for defense.
Read More
Collection Operations: Are They a Necessity in Cybersecurity?
By Charles Joseph · Updated
Intercepted communications, hacked systems, human sources. How information gets gathered, and whether security teams can afford to skip it.
Read More
Computer Forensics: The Future of Cyber Crime Investigation?
By Charles Joseph · Updated
Fraud, cyberstalking, a data breach: the evidence is on a device somewhere. How computer forensics recovers it in a way a court will accept.
Read More
Computer Network Defense: How Robust Can It Be?
By Charles Joseph · Updated
Firewalls, encryption and intrusion detection form the walls. How computer network defense is built, and how strong those walls can get.
Read More
Computer Network Defense Analysis: A Proactive Approach?
By Charles Joseph · Updated
Watching corporate traffic, hardening an online store, protecting a campus network. How defense analysis finds the weak spots before attackers do.
Read More
Computer Network Defense Infrastructure Support: How Vital Is It?
By Charles Joseph · Updated
Firewalls, patches and access controls don't maintain themselves. What infrastructure support involves, and why networks fall apart without it.
Read More
Computer Security Incident: How Prepared Are We?
By Charles Joseph · Updated
An intrusion, a phishing email, someone where they shouldn't be. What counts as a security incident, and how ready most organizations really are.
Read More
Confidentiality: How Can We Assure It in Cyber Space?
By Charles Joseph · Updated
Medical records, bank details, trade secrets. Keeping information away from the wrong eyes is the oldest job in security. How it's done online.
Read More
Consequence: How Dire Can a Cyber Breach Be?
By Charles Joseph · Updated
A breach, a bad download, a missed regulation. The consequences range from embarrassment to ruin. What follows a security failure, with three examples.
Read More
Continuity of Operations Plan: Is It the Ultimate Safeguard?
By Charles Joseph · Updated
Floods, fires, outages and failures. A COOP spells out how a software company, a factory or a shop keeps running through them.
Read More
Critical Infrastructure: How Vulnerable Can It Be to Cyber Attacks?
By Charles Joseph · Updated
Power, water, hospitals and banks. Hit the systems a nation runs on and everything else follows. How vulnerable critical infrastructure really is.
Read More
Critical Infrastructure and Key Resources: Are They Adequately Protected?
By Charles Joseph · Updated
Power plants, hospitals and phone networks sit at the top of every attacker's list. What counts as a key resource, and whether it's protected well enough.
Read More
Cryptanalysis: Is It the Achilles Heel of Cryptography?
By Charles Joseph · Updated
Breaking Enigma won a war. Cracking a password wins a breach. How cryptanalysis takes ciphers apart, and whether it's cryptography's weak spot.
Read More
Cryptographic Algorithm: How Secure Can It Be?
By Charles Joseph · Updated
RSA, AES and SHA-256 are the math behind every secure message. How cryptographic algorithms work, and how secure they can be.
Read More
Cryptography: Is It Foolproof against Cyber Threats?
By Charles Joseph · Updated
Secure email, safe payments and protected passwords all depend on it. How cryptography works, and whether it's foolproof.
Read More
Cryptology: The Silver Bullet in Cybersecurity?
By Charles Joseph · Updated
Making codes and breaking them are two halves of the same science. What cryptology covers, and whether it's the silver bullet security has been looking for.
Read More
Customer Service and Technical Support: Unsuspecting Cybersecurity Hubs?
By Charles Joseph · Updated
The help desk resets passwords, installs antivirus and talks to strangers all day. Why support teams are a security asset, and a target.
Read More
Cyber Ecosystem: Is It Breeding Ground for Cyber Attacks?
By Charles Joseph · Updated
Marketplaces, social platforms and smart devices all live in one connected ecosystem. What that means, and whether it breeds attacks.
Read More
Cyber Exercise: Are We Ready for the Real Deal?
By Charles Joseph · Updated
Tabletop drills, full-scale simulations and red team attacks. How cyber exercises test whether an organization is ready for the real thing.
Read More
Cyber Incident: Can We Prevent It Completely?
By Charles Joseph · Updated
A phishing email, a ransomware outbreak, a file sent to the wrong person. What counts as a cyber incident, and whether any of them can be fully prevented.
Read More
Cyber Incident Response Plan: How Prepared Are We?
By Charles Joseph · Updated
When the breach comes, the plan decides whether you contain it in hours or lose weeks. What a response plan covers, with examples.
Read More
Cyber Infrastructure: Is It the Next Big Attack Target?
By Charles Joseph · Updated
Data centers, cloud storage and the protocols that connect them. What cyber infrastructure includes, and why it's a tempting target.
Read More
Cyber Operations: How Can They Influence National Security?
By Charles Joseph · Updated
Protective measures, traffic monitoring and post-breach investigation. What cyber operations involve, and how they shape national security.
Read More
Cyber Operations Planning: Are We Ahead of the Game?
By Charles Joseph · Updated
Customer data, government agencies and online stores all need a plan before the attack. How cyber operations planning works.
Read More
Cybersecurity: Is It a Losing Battle?
By Charles Joseph · Updated
Antivirus, two-factor authentication and secure Wi-Fi are the everyday face of it. What cybersecurity is, and whether the battle can be won.
Read More
Cyber Threat Intelligence (Cti): Is It the Ultimate Defense Tool?
By Charles Joseph · Updated
Knowing who is coming for you and how is half the defense. What cyber threat intelligence collects, and whether it's the ultimate tool.
Read More
Data Administration: How Crucial Is It in Cyber Defense?
By Charles Joseph · Updated
Policies, standards, quality and privacy. How data administration works in retail, healthcare and startups, and why it matters to defense.
Read More
Data Aggregation: Does It Invite Unwanted Cyber Attention?
By Charles Joseph · Updated
Weather forecasts, health studies and online stores all combine data to see the bigger picture. How aggregation works, and whether it attracts the wrong attention.
Read More
Data Breach: Can We Ever Be Fully Insured?
By Charles Joseph · Updated
An online shop, a healthcare provider, a social platform. How breaches happen, with three examples, and whether you can ever be fully covered.
Read More
Data Integrity: Can It Be Compromised?
By Charles Joseph · Updated
A bank balance, a shopping order, a medical chart: the data has to be right. How integrity is protected, and how it can be compromised.
Read More
Data Leakage: How Can We Prevent It?
By Charles Joseph · Updated
An email to the wrong person, a misconfigured cloud bucket, a lost laptop. How data leaks happen and how to stop them.
Read More
Data Loss: Can It Be Irrecoverable?
By Charles Joseph · Updated
Accidental deletion, failed hardware, a cybercrime. How data gets lost, and whether it can ever be fully recovered.
Read More
Data Loss Prevention: How Effective Are Our Measures?
By Charles Joseph · Updated
Employee monitoring, network controls and cloud security. How DLP tools work, and how effective they really are.
Read More
Data Mining: A Treasure Trove for Cybercriminals?
By Charles Joseph · Updated
Supermarket shelves, Netflix recommendations and fraud detection all come from digging through data. How data mining works, and who else is digging.
Read More
Data Spill: How Damaging Can It Be?
By Charles Joseph · Updated
A misaddressed email, a laptop left in a taxi, a hacker inside the network. How data spills happen and how far the damage can spread.
Read More
Data Theft: How Can We Secure Our Fort?
By Charles Joseph · Updated
Harvested credentials, phishing emails, malware. The three most common ways data gets stolen, and how to make the fort harder to breach.
Read More
Decipher: How Important Is It in Cyber Defense?
By Charles Joseph · Updated
Hsalf Xvod looks like nonsense until you know the trick. What deciphering involves, and why it matters to the people defending networks.
Read More
Decode: Can It Be the First Line of Defense?
By Charles Joseph · Updated
Morse code was the original. Today the same idea turns encoded data back into something usable. What decoding is, and whether it belongs on the front line of defense.
Read More
Decrypt: How Crucial Is It for Cyber Investigators?
By Charles Joseph · Updated
An encrypted email, a secure download, an online banking session: each ends with a decryption step. How it works, and why investigators care so much about it.
Read More
Decryption: How Secure Is It from Intruders?
By Charles Joseph · Updated
The key turns scrambled data back into words. What decryption is, how it protects email, shopping and passwords, and how safe the process is from intruders.
Read More
Denial of Service: How Can It Cripple Systems?
By Charles Joseph · Updated
Buffer overflows, ICMP floods and SYN floods all aim for the same result: a server too busy to answer anyone. How DoS attacks cripple a system.
Read More
Designed-in Security: How Effective Can It Be?
By Charles Joseph · Updated
A software app, an online shop and a smart device, all built with security from day one. What designed-in security looks like, and how effective it can be.
Read More
Digital Forensics: Is It the New Frontier in Cybersecurity?
By Charles Joseph · Updated
Breached networks, court cases and lost data all come down to reading what a device remembers. What digital forensics does, and where the field is heading.
Read More
Digital Rights Management: How Does It Protect Content?
By Charles Joseph · Updated
E-books that won't copy, streams that won't download, games that check in with a server. How DRM protects content, and what it costs the people who paid.
Read More
Digital Signature: Can It Be Forged or Misused?
By Charles Joseph · Updated
A signed email, a verified software download, a legally binding document. How digital signatures prove who sent what, and whether they can be forged.
Read More
Disruption: How Can We Minimize Its Impact?
By Charles Joseph · Updated
A power outage, a crashed website, a hacking attack. What counts as a disruption, and how to keep the damage small.
Read More
Distributed Denial of Service: How Can We Fight Back?
By Charles Joseph · Updated
A gaming server knocked offline, a shop down on sale day, a political site silenced. How DDoS attacks work, and how to fight back.
Read More
Dynamic Attack Surface: Can We Stay One Step Ahead?
By Charles Joseph · Updated
Every update, new device and cloud connection changes where you can be hit. Why the attack surface never sits still, and how to keep up.
Read More
Education and Training: The Answer to Cybersecurity Threats?
By Charles Joseph · Updated
Online courses, workshops and certifications. Why learning is the most underrated defense, and how to go about it.
Read More
Electronic Signature: How Secure Is It?
By Charles Joseph · Updated
Contracts, approvals and confirmations signed from a phone. How electronic signatures work, their legal standing, and how secure they really are.
Read More
Encipher: How Does It Secure Information?
By Charles Joseph · Updated
Email, passwords and payments all get scrambled before they travel. How enciphering turns readable data into a code only the right key can undo.
Read More
Encode: Does It Protect Data from Theft?
By Charles Joseph · Updated
Email, URLs and video files are all encoded for transit. What encoding does, and whether it protects anything from theft.
Read More
Encrypt: How Unbreakable Is It?
By Charles Joseph · Updated
Emails, shopping sessions and Wi-Fi all rely on it. What encryption does, and how unbreakable it really is.
Read More
Encryption: Is It a Perfect Shield for Data?
By Charles Joseph · Updated
HTTPS, AES, PGP and end-to-end: the shields that keep data unreadable. How encryption works, in technical and plain terms, and where it falls short.
Read More
Enterprise Risk Management: Does It Cover Cyber Threats?
By Charles Joseph · Updated
A factory, a bank and a hospital all weigh their risks differently. How ERM works, and whether it takes cyber threats seriously enough.
Read More
Event: Can It Predict a Cybersecurity Incident?
By Charles Joseph · Updated
A login, a spike in error messages, a malware alert. Every event is a clue. How to tell which ones predict a real incident.
Read More
Exfiltration: How Can We Detect It in Time?
By Charles Joseph · Updated
The attackers are already in. Now the data is leaving. How exfiltration happens, and how to catch it before it's gone.
Read More
Exposure: How Can We Minimize Our Digital Footprint?
By Charles Joseph · Updated
Outdated software, weak passwords, an open network. What exposure means, and how to shrink the footprint attackers can see.
Read More
Exploitation Analysis: Can It Provide a Cyber Defense Blueprint?
By Charles Joseph · Updated
Browsers, cloud storage and mobile apps all have doors that could be opened. How exploitation analysis finds them first, and how to turn that into a defense plan.
Read More
Failure: Can It Lead to Catastrophic Cyber Attacks?
By Charles Joseph · Updated
A crashed shop at peak sale, an app that stops working, a data system that gives out. How failures happen, and whether they open the door to attacks.
Read More
Firewall: Can It Be the Ultimate Cyber Guardian?
By Charles Joseph · Updated
Office networks, home routers and personal computers all rely on one. How firewalls work, and whether they can be the ultimate guardian.
Read More
Forensics: Is It the Key to Decoding Cybercrimes?
By Charles Joseph · Updated
A network breach, a stolen laptop, suspected fraud. How forensics recovers the evidence and reconstructs what happened.
Read More
Hacker: How Can We Outsmart Them?
By Charles Joseph · Updated
Social accounts, corporate networks and the ethical ones who break in on purpose. What hackers do, and how to outsmart them.
Read More
Hash Value: Can It Assure Data Integrity?
By Charles Joseph · Updated
A digital fingerprint that changes completely if a single character does. How hash values protect passwords, data and signatures.
Read More
Hashing: How Does It Enhance Data Security?
By Charles Joseph · Updated
Passwords, file checks and blockchains all depend on it. How hashing works, and why one-way is the whole point.
Read More
Hazard: What Are the Cyber Threats We Overlook?
By Charles Joseph · Updated
An unlocked door, a wet floor, a careless download. What a hazard is, and the cyber threats we tend to overlook.
Read More
Ict Supply Chain Threat: Is It Underestimated?
By Charles Joseph · Updated
Hardware altered at the factory, software tampered with in transit, parts made where they shouldn't be. Why supply chain threats get less attention than they deserve.
Read More
Identity and Access Management: Is It Foolproof?
By Charles Joseph · Updated
Onboarding, role-based access and password resets all run through IAM. How it verifies who you are and what you may touch, and where it still slips.
Read More
Impact: How Devastating Can a Cyber Attack Be?
By Charles Joseph · Updated
A small shop, a hospital network, one person's laptop. What a cyber attack actually costs, in three examples.
Read More
Incident Management: Are We Ready for the Unforeseen?
By Charles Joseph · Updated
A server crash, a slow website, a suspicious email. How incident management turns each into a process instead of a panic.
Read More
Incident: Can We Predict It before It Happens?
By Charles Joseph · Updated
A hacked database, a phishing campaign, a server flooded offline. What counts as an incident, and whether you can see one coming.
Read More
Incident Response: How Swift Can We Be?
By Charles Joseph · Updated
A data breach, a government site under attack, ransomware in the corporate network. How incident response unfolds, step by step, and how fast it can move.
Read More
Incident Response Plan: Is Ours Resilient Enough?
By Charles Joseph · Updated
An online shop, a government department and a tech firm all need a plan before the breach. What goes into one, and how to tell if yours is strong enough.
Read More
Indicator: How Reliable Can It Be In Predicting Attacks?
By Charles Joseph · Updated
Unexpected traffic, a new admin account, a system that's suddenly slow. How indicators of compromise work, and how much they can predict.
Read More
Industrial Control System: How Secure Are They from Attacks?
By Charles Joseph · Updated
Power plants, water treatment and factory floors run on systems built long before cyber attacks were a concern. How ICS works, and how exposed it is.
Read More
Information and Communications Technology: A Double-Edged Sword?
By Charles Joseph · Updated
Teleconferencing, email, mobile phones: ICT runs modern life. What the term covers, and why every convenience is also a risk.
Read More
Information Assurance: Can We Guarantee It?
By Charles Joseph · Updated
Authentication, firewalls and backups all serve one promise: the data stays right, private and available. What information assurance means, and whether it can be guaranteed.
Read More
Information Security Policy: How Robust Is Ours?
By Charles Joseph · Updated
Password rules, internet use, access control. What an information security policy covers, and how to tell if yours has teeth.
Read More
Information Sharing: Does It Expose Us to Risks?
By Charles Joseph · Updated
Medical teams share records, companies release code, researchers swap data. How information sharing works, and the risks that come with openness.
Read More
Information System Resilience: Can It Withstand Cyber Attacks?
By Charles Joseph · Updated
An online shop, a bank and a hospital records system all have to keep running under attack. What resilience means, and how it's built.
Read More
Information Systems Security Operations: How Proactive Are We?
By Charles Joseph · Updated
Firewalls, audits and awareness training. What security operations involve day to day, and how proactive most teams really are.
Read More
Information Technology: How Secure Is Our Infrastructure?
By Charles Joseph · Updated
Networks, software and cloud storage: the whole machinery of modern business. What IT covers, and how secure the foundation is.
Read More
Insider Threat: The Elephant in the Cyber Room?
By Charles Joseph · Updated
A careless employee, a bitter ex-colleague, a contractor who cut corners. Why the biggest risk is often already inside the building.
Read More
Integrated Risk Management: Does It Cover All Cyber Threats?
By Charles Joseph · Updated
A retailer, a manufacturer and a software firm all juggle risks across departments. How integrated risk management works, and whether cyber gets its share.
Read More
Integrity: Can We Really Safeguard Information?
By Charles Joseph · Updated
A bank transfer, a saved document, a sent email: each has to arrive exactly as intended. What integrity means, and whether it can really be safeguarded.
Read More
Intent: Can We Predict a Hacker’s Next Move?
By Charles Joseph · Updated
Checking email, downloading work files, trying to crack a password. Same keyboard, different intent. How understanding motive helps predict the next move.
Read More
Interoperability: Is It a Cybersecurity Risk or Benefit?
By Charles Joseph · Updated
Systems that talk to each other make life easier, in healthcare and everywhere else. Whether that openness is a security benefit or a risk.
Read More
Intrusion Detection: How Effective Can It Be?
By Charles Joseph · Updated
Network monitoring, suspicious logins, odd application behavior. How intrusion detection works, and how much of the picture it really catches.
Read More
Intrusion: Can It Be Detected in Real-Time?
By Charles Joseph · Updated
Phishing emails, malware and unauthorized logins. What an intrusion looks like, and whether it can be caught as it happens.
Read More
Investigate: Can It Help Us Stay Ahead of Hackers?
By Charles Joseph · Updated
A traffic drop, a struggling student, a failed part. What investigation means, with three examples, and how the habit keeps you ahead of attackers.
Read More
Investigation: How Critical Is It Post a Cyber Incident?
By Charles Joseph · Updated
A data leak, a suspicious email, strange activity in a bank account. How investigations work after an incident, and why they matter.
Read More
It Asset: How Vulnerable Are They to Cyber Attacks?
By Charles Joseph · Updated
Hardware, software and data: everything the company owns that an attacker might want. What IT assets are, and how exposed they tend to be.
Read More
Knowledge Management: How Can It Boost Cybersecurity?
By Charles Joseph · Updated
Capture what the organization knows, store it safely, share it with the right people. How knowledge management works, and how it strengthens security.
Read More
Legal Advice and Advocacy: Essential in Cybersecurity Battles?
By Charles Joseph · Updated
A small business, a patent fight, a consumer group. Why legal advice and advocacy belong in the cybersecurity conversation.
Read More
Machine Learning and Evolution: Are They the Future of Cybersecurity?
By Charles Joseph · Updated
Netflix recommendations, spam filters and the smartphone itself. What machine learning and technological evolution mean, and whether they're the future of security.
Read More
Macro Virus: Can It Be Stopped in Its Tracks?
By Charles Joseph · Updated
A Word or Excel file opens, and the macro runs. How macro viruses spread through documents, and whether they can be stopped.
Read More
Malicious Applet: How Damaging Can It Be?
By Charles Joseph · Updated
A keylogger, an adware applet, a virus applet. What a malicious applet does once it's on your machine, and how much damage it can cause.
Read More
Malicious Code: Can It Be Detected before It Spreads?
By Charles Joseph · Updated
Viruses, trojans and spyware, often hiding in free downloads and attachments. What malicious code does, and whether it can be caught before it spreads.
Read More
Malicious Logic: Can It Be Hidden in Plain Sight?
By Charles Joseph · Updated
Viruses, worms and trojans by another name. What malicious logic is, and how it hides in plain sight.
Read More
Malware: How Can We Be Safe from It?
By Charles Joseph · Updated
Viruses, ransomware and spyware, explained with examples. What malware is, and how to stay safe from it.
Read More
Mitigation: Are Our Strategies Strong Enough?
By Charles Joseph · Updated
Data management, an online shop, a smartphone app. How mitigation reduces the damage before it happens, and how to tell if your strategy is strong enough.
Read More
Moving Target Defense: A New Age Cybersecurity Strategy?
By Charles Joseph · Updated
Change the locks before the thief finishes picking them. How randomized addresses, memory and configurations keep attackers guessing.
Read More
Network Resilience: Can We Ensure It Amidst Cyber Threats?
By Charles Joseph · Updated
Redundancy, diversity and automation. How a network keeps running through hardware failures, outages and attacks.
Read More
Network Services: How Secure Are They from Intrusions?
By Charles Joseph · Updated
Email, file transfer and printing, all delivered over the network. What network services are, and how secure they are from intrusion.
Read More
Non-repudiation: Can It Guarantee Transaction Security?
By Charles Joseph · Updated
You can't claim you never sent it, and they can't claim they never got it. How non-repudiation works for contracts, email and banking.
Read More
Object: How Secure Can It Be In Cyberspace?
By Charles Joseph · Updated
Files, applications and database records are all objects. What the term means, and how secure an object can be.
Read More
Operate and Maintain: Does It Ensure System Security?
By Charles Joseph · Updated
A website, an IT department, an online store. What it takes to keep a system running and secure, day after day.
Read More
Operational Exercise: Are We Ready for Real-World Cyber Attacks?
By Charles Joseph · Updated
A hospital emergency drill, a bank's attack simulation, a factory line test. How operational exercises reveal whether you're ready.
Read More
Operations Technology: How Secure Is It from Cyber Threats?
By Charles Joseph · Updated
Assembly lines, power plants and traffic lights run on OT. What makes it different from IT, and how secure it is from attack.
Read More
Outsider Threat: Are They the Biggest Cybersecurity Threat?
By Charles Joseph · Updated
Hackers, spies and phishers grab the headlines. Whether they really are the biggest threat, with three examples of what they do.
Read More
Oversight and Development: Can They Ensure Cybersecurity?
By Charles Joseph · Updated
A bakery and a software company have more in common than you'd think. How oversight and development work together to keep systems secure.
Read More
Passive Attack: Can It Go Undetected?
By Charles Joseph · Updated
No damage, no alarms, just quiet listening. How passive attacks eavesdrop, analyze traffic and intercept email, and whether they can be caught.
Read More
Password: How Strong Can It Really Be?
By Charles Joseph · Updated
Email accounts, ATMs and online platforms all come down to one secret string. What a password is, and how strong it can really be.
Read More
Pen Test: Can It Reveal Our Cybersecurity Weaknesses?
By Charles Joseph · Updated
A simulated attack on your own systems, to find the holes before someone else does. How pen tests work, with examples.
Read More
Penetration: Can It Be the First Sign of a Breach?
By Charles Joseph · Updated
Getting in is the point, whether you're a hired expert or an intruder. What penetration means, and whether it signals a breach.
Read More
Penetration Testing: How Effective Is It in Revealing Vulnerabilities?
By Charles Joseph · Updated
Web apps, networks and people themselves can all be tested. How penetration testing works, and how much it reveals.
Read More
Personal Identifying Information: Is It Safe from Cybercriminals?
By Charles Joseph · Updated
Your name, your address, your Social Security number. What counts as PII, and how safe it is from criminals.
Read More
Personally Identifiable Information: How Can We Protect It?
By Charles Joseph · Updated
A vehicle plate, a full name, an email address. What personally identifiable information includes, and how to protect it.
Read More
Phishing: Can We Spot It before Falling for It?
By Charles Joseph · Updated
Email scams, social media lures and fake tech support. How phishing works, and whether you can spot it before you click.
Read More
What Is Plaintext?
By Charles Joseph · Updated
Email, HTML and text messages before anyone scrambles them. What plaintext is, and why it matters.
Read More
Precursor: Can It Warn Us about Impending Cyber Attacks?
By Charles Joseph · Updated
Dark clouds before rain, bird migration before the season turns, chatter before a sales spike. How precursors warn of what's coming, in security too.
Read More
Preparedness: How Ready Are We for a Cyber Incident?
By Charles Joseph · Updated
IT drills, company emergency plans and personal finances. What preparedness means, and how ready most organizations are.
Read More
Privacy: Can It Be Ensured in the Digital Age?
By Charles Joseph · Updated
Your shopping, your social media, your browsing history. What privacy means online, and whether it can still be ensured.
Read More
Private Key: How Secure Can It Be?
By Charles Joseph · Updated
The secret half of the pair, for email, cryptocurrency and secure websites. How a private key works, and how secure it can be.
Read More
Protect and Defend: Are We Equipped for the Cyber War?
By Charles Joseph · Updated
An e-commerce business, a school system, a bank. What protect and defend means in practice, and whether most are equipped.
Read More
Public Key: How Secure Can It Be?
By Charles Joseph · Updated
The half of the pair you share with the world. How public keys secure email, websites and signatures, and how secure they are.
Read More
Public Key Cryptography: Is It a Reliable Security Measure?
By Charles Joseph · Updated
Encrypt with one key, decrypt with the other. How public key cryptography works, and whether it's reliable.
Read More
Public Key Encryption: Can It Secure Our Communications?
By Charles Joseph · Updated
Email, websites and cloud storage all depend on it. How public key encryption works, and whether it can secure your communications.
Read More
Public Key Infrastructure: How Secure Can It Be?
By Charles Joseph · Updated
Email, websites and VPNs trust certificates managed by PKI. What the infrastructure includes, and how secure it can be.
Read More
Recovery: How Quick Can We Bounce Back after a Breach?
By Charles Joseph · Updated
Ransomware, DDoS and a compromised email server. How recovery brings systems back, and how quickly.
Read More
Red Team Exercise: How Effective Is It in Enhancing Security?
By Charles Joseph · Updated
A full-scale simulated attack to test preparedness. How red team exercises work, and how effective they are.
Read More
Red Team: The Offensive Side of Cybersecurity
By Charles Joseph · Updated
Professionals who attack your systems so real attackers can't. How red teams work for software companies, e-commerce and banks.
Read More
Redundancy: Can It Guarantee System Availability?
By Charles Joseph · Updated
Multiple hard drives, backup generators, dual internet providers. How redundancy keeps systems available, and whether it can guarantee it.
Read More
Resilience: How Can We Build It in Our Cyber Defense?
By Charles Joseph · Updated
Backup servers, uninterruptible power and auto-syncing cloud storage. How resilience is built into cyber defense.
Read More
Response: How Quick Can We Be in a Cyber Incident?
By Charles Joseph · Updated
A virus detected, a phishing attempt, an unauthorized login. How response works in a cyber incident, and how quick it can be.
Read More
Response Plan: Are We Ready for the Worst?
By Charles Joseph · Updated
A natural disaster, a data breach, a product failure. What a response plan covers, and whether you're ready for the worst.
Read More
Risk: Can It Be Totally Eliminated in Cyberspace?
By Charles Joseph · Updated
Email scams, weak passwords, unprotected networks. What risk means in cyberspace, and whether it can ever be eliminated.
Read More
Risk Analysis: How Accurate Can It Be?
By Charles Joseph · Updated
A product launch, a bank loan, a software project. How risk analysis works, and how accurate it can be.
Read More
Risk Assessment: Can It Forecast All Potential Threats?
By Charles Joseph · Updated
A software company, a bank, an e-commerce business. How risk assessment identifies threats, and whether it can forecast them all.
Read More
Risk Management: Can It Protect Us from All Cyber Threats?
By Charles Joseph · Updated
Firewalls, employee training and backups. How risk management works, and whether it can protect against every threat.
Read More
Risk Mitigation: Are Our Strategies Effective Enough?
By Charles Joseph · Updated
Antivirus, patching and training. How risk mitigation reduces damage, and whether your strategies are effective enough.
Read More
Risk-Based Data Management: Is It the Answer to Security Threats?
By Charles Joseph · Updated
Healthcare, retail and online business. How risk-based data management prioritizes protection, and whether it's the answer.
Read More
Secret Key: How Secure Is It from Intruders?
By Charles Joseph · Updated
One key for both locking and unlocking. How secret keys secure email, payments and VPNs, and how safe they are from intruders.
Read More
Securely Provision: Can It Guarantee System Security?
By Charles Joseph · Updated
Secure coding, account management and encryption keys, from day one. How secure provisioning works for web, network and mobile development.
Read More
Security Automation: Is It the Future of Cybersecurity?
By Charles Joseph · Updated
Threat detection, routine checks and incident response without human intervention. How security automation works, and whether it's the future.
Read More
Security Incident: How Can We Respond Effectively?
By Charles Joseph · Updated
Phishing, ransomware, malware infection. What a security incident is, and how to respond effectively.
Read More
Security Policy: Does It Cover All Aspects of Cybersecurity?
By Charles Joseph · Updated
Passwords, internet use, breach response. What a security policy covers, and whether it covers enough.
Read More
Security Program Management: How Robust Is Ours?
By Charles Joseph · Updated
Planning, goals, risks and continuous improvement. How security program management works, and how robust yours is.
Read More
Signature: How Is It Used to Protect Us?
By Charles Joseph · Updated
A worm's code, a trojan's connection, a tampered system file. How signatures let security software recognize what it has seen before.
Read More
Situational Awareness: Can It Help in Cyber Defense?
By Charles Joseph · Updated
Driving, cooking, hiking: knowing what's going on around you. Why situational awareness is a cyber defense skill as well.
Read More
Software Assurance and Security Engineering: Is It Foolproof?
By Charles Joseph · Updated
Antivirus, e-commerce sites and banking apps need both. How assurance and security engineering fit together, and whether they're foolproof.
Read More
Software Assurance: Can It Ensure Cybersecurity?
By Charles Joseph · Updated
Quality, reliability and security built into the process. How software assurance works for development, updates and cloud services, and whether it can guarantee cybersecurity.
Read More
Spam: Is It Just Annoying or Dangerous?
By Charles Joseph · Updated
Weight-loss miracles, fake sweepstakes, unwanted promotions. What spam is, and when it crosses from annoying into dangerous.
Read More
Spillage: How Can We Prevent It?
By Charles Joseph · Updated
Classified information in the wrong hands, by accident or design. What spillage is, and how to prevent it.
Read More
Spyware: How Invisible Can It Be?
By Charles Joseph · Updated
Keyloggers, adware and trojans quietly collecting what you do. What spyware is, and how invisible it can be.
Read More
What Is Spoofing?
By Charles Joseph · Updated
A letter with a false return address, for the digital age. How email, caller ID and website spoofing work.
Read More
Strategic Planning and Policy Development: How Vital Are They for Cybersecurity?
By Charles Joseph · Updated
Long-term goals and the rules that guide the way there. How planning and policy shape cybersecurity, with examples.
Read More
Subject: How Can It Be Secured in Cyberspace?
By Charles Joseph · Updated
An IT admin, an automated email system, a security scanner. What a subject is in security, and how it's secured.
Read More
Supervisory Control and Data Acquisition: Can It Be Fully Secured?
By Charles Joseph · Updated
Power, water and oil all run on SCADA systems. What they do, and whether they can be fully secured.
Read More
Supply Chain Risk Management: How Effective Can It Be?
By Charles Joseph · Updated
A phone maker, a supermarket, a clothing retailer. How supply chain risk management keeps goods flowing, and how effective it can be.
Read More
Supply Chain: How Vulnerable Is It to Cyber Attacks?
By Charles Joseph · Updated
From raw materials to delivered product, across tech, fashion and food. What a supply chain is, and how vulnerable it is to attack.
Read More
Symmetric Cryptography: Can It Secure Our Data?
By Charles Joseph · Updated
WhatsApp, email and file sharing use one shared key. How symmetric cryptography works, and whether it can secure your data.
Read More
Symmetric Encryption Algorithm: Is It Reliable Enough?
By Charles Joseph · Updated
SSL, AES and DES all use a single secret key. How symmetric algorithms work, and whether they're reliable enough.
Read More
Symmetric Key: How Secure Can It Be?
By Charles Joseph · Updated
One key, kept private, for email, banking and file transfer. How symmetric keys work, and how secure they can be.
Read More
System Administration: Can It Shield Us from Cyber Threats?
By Charles Joseph · Updated
A tech company, a school, a retail store. What system administrators do, and whether they can shield us from threats.
Read More
System Integrity: How Can We Ensure It?
By Charles Joseph · Updated
Passwords, updates and backups keep a system in its ideal state. What integrity means, and how to ensure it.
Read More
Systems Development: Can It Be Vulnerable to Cyber Threats?
By Charles Joseph · Updated
An online shop, custom business software, a school system. How systems development works, and where cyber threats creep in.
Read More
Systems Requirements Planning: Does It Consider Cybersecurity?
By Charles Joseph · Updated
Hardware, software and network, defined before the build. How requirements planning works, and whether security gets a seat.
Read More
Systems Security Analysis: How Important Is It?
By Charles Joseph · Updated
Outdated software, open Wi-Fi, unencrypted data. How systems security analysis finds the weak points, and why it matters.
Read More
Systems Security Architecture: Can It Protect Our Cyber Infrastructure?
By Charles Joseph · Updated
A bank, an e-commerce platform, a healthcare provider. How security architecture is designed, and whether it can protect the infrastructure.
Read More
Tabletop Exercise: How Effective Is It for Cybersecurity Training?
By Charles Joseph · Updated
An earthquake, a breach, a product recall, all talked through before they happen. How tabletop exercises work, and how effective they are.
Read More
Tailored Trustworthy Space: Is It Achievable in Cybersecurity?
By Charles Joseph · Updated
Medical databases, banking platforms and internal comms built as safe zones. What a tailored trustworthy space is, and whether it's achievable.
Read More
Targets: Who Are the Most Vulnerable to Cyber Attacks?
By Charles Joseph · Updated
Online retailers, government networks, personal computers. What makes a target, and who is most vulnerable.
Read More
Technology Research and Development: Are They the Key to Better Cybersecurity?
By Charles Joseph · Updated
Machine learning software, high-capacity storage, secure transactions. How tech R&D works, and whether it's the key to better security.
Read More
Test and Evaluation: Are They Crucial for Cybersecurity Solutions?
By Charles Joseph · Updated
Mobile apps, cars and food products all get tested. What test and evaluation involves, and why security solutions need it.
Read More
Threat Actor: Can We Unmask Them before They Strike?
By Charles Joseph · Updated
A lone hacker, an organized crime group, a nation-state. Who threat actors are, and whether they can be unmasked first.
Read More
Threat: How Can We Predict the Next Big One?
By Charles Joseph · Updated
A scam email, a virus, a hack. What a threat is, and whether the next big one can be predicted.
Read More
Threat Agent: Who Can Be the Unseen Cyber Enemy?
By Charles Joseph · Updated
Hackers, malware and disgruntled employees. What a threat agent is, and who the unseen enemy might be.
Read More
Threat Analysis: How Accurate Can It Be?
By Charles Joseph · Updated
A company website, a smartphone user, a bank transaction. How threat analysis works, and how accurate it can be.
Read More
Threat Assessment: How Vital Is It in Cybersecurity Strategy?
By Charles Joseph · Updated
An online store, a social platform, a corporate office. How threat assessment works, and why it's vital to strategy.
Read More
Ticket: How Can It Help in Resolving Cyber Issues?
By Charles Joseph · Updated
A digital pass issued at login, for email, corporate networks and shopping. How tickets work in authentication.
Read More
Traffic Light Protocol: How Effective Is It in Information Sharing?
By Charles Joseph · Updated
Red, amber, green, white: how sensitive is this information? How TLP guides sharing, and how effective it is.
Read More
Unauthorized Access: How Can We Prevent It?
By Charles Joseph · Updated
A student intruder, a corporate hacker, a curious employee. How unauthorized access happens, and how to prevent it.
Read More
Vulnerability: Can It Be Detected before It’s Exploited?
By Charles Joseph · Updated
An outdated system, a weak password, a programming error. What a vulnerability is, and whether it can be found before it's exploited.
Read More
Vulnerability Assessment and Management: Are They Key to Cyber Defense?
By Charles Joseph · Updated
An e-commerce site, an online bank, a mobile game studio. How vulnerabilities are found, ranked and fixed, and whether the process is the key to defense.
Read More
Weakness: Can We Identify Ours before They’re Exploited?
By Charles Joseph · Updated
A bug, a misconfiguration, a missing control. What a weakness is, and whether you can find yours before an attacker does.
Read More
White Team: Are They the Unseen Heroes of Cybersecurity?
By Charles Joseph · Updated
While red attacks and blue defends, someone sets the rules and keeps score. What the white team does in a security exercise.
Read More
Information Assurance Compliance: Is It Enough for Security?
By Charles Joseph · Updated
Password policies, HIPAA rules and patch schedules. What compliance requires, and whether ticking the boxes actually makes you secure.
Read More
Work Factor: How Can It Impact Our Cybersecurity?
By Charles Joseph · Updated
How much effort does it take to break in? How password complexity, multi-factor authentication and encryption raise the price of an attack.
Read More
Digital Certificate: How Trustworthy Is It?
By Charles Joseph · Updated
A virtual passport for websites, email and software updates, stamped by an authority you're asked to trust. How certificates work, and how much trust they deserve.
Read More
What Is JavaScript-Binding-Over-HTTP (JBOH)?
By Charles Joseph · Updated
AJAX, REST and JSON working together so web apps feel alive. What JBOH is, in technical and plain terms.
Read More
NOR Flash: Vulnerable to Cyber Threats?
By Charles Joseph · Updated
Byte-level reads and writes make it the fast memory in cameras, phones and cars. What NOR flash is, and whether it's vulnerable.
Read More
SSO: An Avenue for Cyber Breaches?
By Charles Joseph · Updated
One login for Google, social media or the whole office. How single sign-on works, and whether it opens an avenue for breaches.
Read More
PaaS: Increased Cybersecurity Risk?
By Charles Joseph · Updated
Google App Engine, Heroku and Elastic Beanstalk take the infrastructure off your hands. Whether platform as a service adds risk along with convenience.
Read More
Identity Cloning: How Safe Are You?
By Charles Joseph · Updated
A lost wallet, a twin's name, a stranger's details. Three stories of identity cloning, and what they say about how safe you really are.
Read More
What Is Code Stylometry?
By Charles Joseph · Updated
Programmers have a handwriting of their own, even when they try to hide it. How code stylometry identifies authors, catches plagiarism and breaks anonymity.
Read More
CND (Computer Network Defense) Explained
By Charles Joseph · Updated
Antivirus, firewalls and regular scans: the basics of defending a network. What computer network defense involves, with examples.
Read More
Hybrid Malware: The Next Big Threat?
By Charles Joseph · Updated
A virus and a trojan, ransomware and a worm, adware and spyware. How hybrid malware combines threats, and whether it's the next big one.
Read More
OWASP: Still a Relevant Security Resource?
By Charles Joseph · Updated
The Top Ten, ZAP and the cheat sheets come from one volunteer community. What OWASP offers, and whether it's still the resource it used to be.
Read More
Malvertising: Can Ads Undermine Your Security?
By Charles Joseph · Updated
Pop-ups, redirects and ads that masquerade as something else. How malvertising slips malware into legitimate ad networks.
Read More
Understanding BGP: The Internet’s Routing Protocol
By Charles Joseph · Updated
Two engineers sketched it in 1989, and it still decides how your data crosses the internet. BGP, explained with and without the jargon.
Read More
JWT: How Secure Are Your Tokens?
By Charles Joseph · Updated
Compact, signed tokens that carry claims between parties. How JSON Web Tokens work for login, data exchange and microservices, and how secure they really are.
Read More
DLP (Data Loss Prevention) Explained
By Charles Joseph · Updated
Blocked emails, discovered secrets, stopped cloud uploads. What DLP tools do, and whether they're worth the money when a breach costs millions.
Read More
Email Blocklist: How Effective?
By Charles Joseph · Updated
Spam, promotions and phishing stopped before they reach you. How email blocklists work, and how effective they are at keeping the inbox clean.
Read More
OSINT: Are We Leaking Too Much?
By Charles Joseph · Updated
Annual reports, social media, even the weather. How open source intelligence is gathered from public sources, and how to stop giving away too much.
Read More
TLS: A Flawless Encryption Method?
By Charles Joseph · Updated
Email, shopping and banking all travel inside it. How TLS works, and whether it's flawless.
Read More
What Is Cryptojacking?
By Charles Joseph · Updated
Your computer is mining cryptocurrency for someone else, and the only sign is a slow machine. How cryptojacking spreads by email, website and server.
Read More
Cyberattack: Are We Truly Prepared?
By Charles Joseph · Updated
Phishing, ransomware and denial of service, explained through examples. What a cyberattack looks like, and whether anyone is truly ready.
Read More
What Is a Deauthentication Attack?
By Charles Joseph · Updated
A student knocks the whole class off Wi-Fi during a test. A stranger in the coffee shop does the same. How deauth attacks work, and how common they are.
Read More
What Is a Local Area Network (LAN)?
By Charles Joseph · Updated
Office, home and school networks are all LANs. What they share, how they're managed, and where you'll find them.
Read More
What Is Eavesdropping?
By Charles Joseph · Updated
Overheard conversations, intercepted email, a sniffer on the network. How eavesdropping works online, and how to keep your words private.
Read More
Outsourcing: A Security Risk to Consider?
By Charles Joseph · Updated
App development, deliveries and payroll handed to outside firms. What outsourcing saves, and the security risks it brings in through the side door.
Read More
Security Perimeter: Is It Enough Anymore?
By Charles Joseph · Updated
A company firewall, a store's Wi-Fi, a university network. What the perimeter is, and whether it's still enough.
Read More
Tripwire: The Hidden Line of Defense?
By Charles Joseph · Updated
A snapshot of your files, and an alarm when anything changes. How tripwires protect networks, websites and bank data, and how well they work.
Read More
Rogue Security Software: Friend or Foe?
By Charles Joseph · Updated
Fake antivirus, deceptive disk cleaners, phony spyware removal. How scareware tricks you, and how to tell friend from foe.
Read More
What Is a Block Cipher?
By Charles Joseph · Updated
AES, DES and Triple DES all encrypt data one chunk at a time. How block ciphers differ from stream ciphers, and which ones still matter.
Read More
PKI: An Effective Cybersecurity Safeguard?
By Charles Joseph · Updated
Certificates, keys and the authorities that vouch for them. How public key infrastructure secures email, websites and signatures, and how effective it is.
Read More
RAM Scraping Attack: An Overlooked Threat?
By Charles Joseph · Updated
Card numbers and credentials sit unencrypted in memory while in use. How RAM scraping steals them from retail, banking and e-commerce systems.
Read More
Diffie Hellman Key Exchange: Always Secure?
By Charles Joseph · Updated
Two parties create the same secret key without ever sending it. How the exchange secures email, VPNs and file transfers, and whether it's always safe.
Read More
NAND Flash: Resistant to Cyber-attacks?
By Charles Joseph · Updated
The memory in your camera, phone and USB stick. What NAND flash is, and whether it can be attacked.
Read More
Malicious Mobile App: The Unseen Danger?
By Charles Joseph · Updated
A weather app, a free game, a productivity tool, each hiding something. How malicious mobile apps work, and how to spot one.
Read More
Clickjacking: How Vulnerable Are Our Clicks?
By Charles Joseph · Updated
You thought you clicked Like. You actually clicked something else entirely. How invisible layers hijack your clicks, from social buttons to online votes.
Read More
What Is a Lightweight Agent?
By Charles Joseph · Updated
Antivirus, load balancers and system monitors that do their job without slowing you down. What makes an agent lightweight, with examples.
Read More
Browser Hijacker: The Invisible Online Terror?
By Charles Joseph · Updated
Your homepage changed, your search engine is different, and the pop-ups won't stop. What a browser hijacker is doing, and why it's more than an annoyance.
Read More
3-Way Handshake: Is It Secure?
By Charles Joseph · Updated
Every web page, email and download starts with the same three-step exchange. What the handshake actually does, and whether it can be trusted.
Read More
Netmask: What Is Its Function in Networking?
By Charles Joseph · Updated
Like an area code for IP addresses, splitting network from host. How netmasks work, with subnetting and CIDR explained.
Read More
Switched Network: What Is It and What Are Its Advantages?
By Charles Joseph · Updated
A city of buildings connected by roads. What a switched network is, how it differs from circuit switching, and its advantages.
Read More
What Is CORS?
By Charles Joseph · Updated
Your website wants data from another site, and the browser says no. CORS is the permission slip that changes the answer. The pizza-delivery version.
Read More
Web Server: How to Secure a Web Server?
By Charles Joseph · Updated
Apache, IIS and Nginx deliver most of the web. What a web server does, how to secure one, and the usage numbers.
Read More
Wiretapping: How to Prevent Wiretapping?
By Charles Joseph · Updated
Law enforcement, criminals and corporate spies all listen in. How wiretapping works, physically and digitally, and whether it can be prevented.
Read More
Zero-Day Attack: How to Defend Against?
By Charles Joseph · Updated
The vulnerability is exploited before the vendor even knows it exists. How zero-day attacks unfold, and how to defend against them.
Read More
Honey Pot: How Effective Are They?
By Charles Joseph · Updated
A decoy system that invites attackers in and watches everything they do. How honey pots work, how to build one, and how effective they are.
Read More
SOCKS: Does the SOCKS Protocol Enhance Privacy?
By Charles Joseph · Updated
A proxy protocol that handles any kind of traffic. How SOCKS works for anonymous browsing, private calls and business transfers, and whether it enhances privacy.
Read More
Decapsulation: What’s Its Role in Networking?
By Charles Joseph · Updated
Every layer of the network wraps your data in headers on the way out and peels them off on the way in. How decapsulation works for email, video and the web.
Read More
Gnutella: How Secure Is the Gnutella Network?
By Charles Joseph · Updated
Share files directly with strangers, no central server required. How Gnutella works, and what it exposes about you.
Read More
Zero-Day: How to Defend Against Them?
By Charles Joseph · Updated
A flaw the developers have had zero days to fix. What a zero-day is, with examples from browsers to banking, and the best practices for defending against one.
Read More
CVSS: How Reliable Is Its Score?
By Charles Joseph · Updated
A score from 0 to 10 tells you how bad a vulnerability is. How CVSS calculates it, where it came from, and how much to trust the number.
Read More
WHOIS: How to Use WHOIS for Security Investigations?
By Charles Joseph · Updated
The internet's phone book for domains and IP addresses. How WHOIS works, how to use the command, and how it helps investigate suspicious email.
Read More
Jump Bag: What Should It Contain?
By Charles Joseph · Updated
When the network goes down at 2 a.m., the right tools had better be packed. What a network engineer's and a sysadmin's jump bag should contain.
Read More
NAT: How Does It Protect Your Network?
By Charles Joseph · Updated
One public address, many private devices behind it. How NAT works at home, at the office and at the ISP, and how it shields your network.
Read More
Router: How Secure Is Your Router?
By Charles Joseph · Updated
Home setups, offices and public Wi-Fi all run through one. What a router does, in technical and plain terms, and how secure yours is.
Read More
Wired Equivalent Privacy (WEP): Why Is WEP Considered Insecure?
By Charles Joseph · Updated
It promised wired-level security for Wi-Fi and delivered something far weaker. Why WEP is insecure, with a password-cracking video.
Read More
Topology: How Does Network Topology Affect Security?
By Charles Joseph · Updated
Star, bus, mesh: the shape of the network. How topology affects security, with examples.
Read More
Wardriving: How to Safeguard Against It?
By Charles Joseph · Updated
A laptop, a car and a city full of unprotected Wi-Fi. How wardriving works, and how to keep your access point off the map.
Read More
SYN Flood: How to Mitigate an Attack?
By Charles Joseph · Updated
Thousands of half-finished handshakes until the server gives up. How SYN floods work, what SYN cookies do, and how to mitigate an attack.
Read More
Threat Model: Why Is Threat Modeling Crucial in Security Design?
By Charles Joseph · Updated
Cloud storage, online banking, e-commerce. How threat modeling identifies, prioritizes and counters threats in security design.
Read More
How Does a Spanning Port Work?
By Charles Joseph · Updated
One port on the switch gets a copy of everything. How spanning ports help with troubleshooting, security monitoring and performance.
Read More
Radio Waves: Explained
By Charles Joseph · Updated
From wave basics to the electromagnetic spectrum and electromagnetism. A full explainer on the radio waves behind modern communication.
Read More
Syslog: Why Is Syslog Important for Network Monitoring?
By Charles Joseph · Updated
Every device's logs, gathered in one place. What syslog is, and why it's the heart of network monitoring.
Read More
Tutorials
21 articles Date
Developer APIs
By Charles Joseph · Updated
Images, weather, stock trades and PDFs, all free. Forty APIs worth bookmarking, from a video by CodingWithLewis.
Read More
What the $!$*$@ … Bash Shell Variables
By Charles Joseph · Updated
Nobody memorizes $!, $* and $@, so here's a script that shows what each one does. Bash's special variables, demonstrated instead of defined.
Read More
How to Filter “access.log” Columns Using AWK
By Charles Joseph · Updated
Nine columns of web server logs, and you only need two. How AWK's FPAT pulls exactly the fields you want.
Read More
How to Get All IP Addresses From a File Using RegEx and PowerShell
By Charles Joseph · Updated
No grep on Windows? A Linux admin's workaround for pulling every unique IP address out of a text file with PowerShell.
Read More
Incident Response and Live Forensics on Linux Cheat Sheet
By Charles Joseph · Updated
User accounts, logs, processes, services and files. The commands to run on a Linux box in the first hour of an incident, based on vm32's GitHub repository.
Read More
Incident Response and Live Forensics Cheat Sheet (Linux and Windows Commands Side-By-Side)
By Charles Joseph · Updated
cat /etc/passwd on one side, net user on the other. The incident response commands for Linux and Windows, matched line by line.
Read More
How to Remove EXIF Data From Your Images
By Charles Joseph · Updated
The photo you just posted may carry your home's coordinates. What EXIF data reveals, and how to strip it on Ubuntu and macOS.
Read More
How to Show the Request and Response Headers in VSCode using the REST Client
By Charles Joseph · Updated
Authentication problems, redirect loops and caching issues all live in the headers. How to see them in VSCode's REST Client.
Read More
Chrome Extension: Remove YouTube Suggestions
By Charles Joseph · Updated
YouTube's suggestions are designed to keep you watching. One small extension removes them, and here's how to install it now that it's gone from the store.
Read More
How to Disable WP Optimize From Creating “wpo-plugins-tables-list.json”
By Charles Joseph · Updated
A popular WordPress plugin quietly lists all your plugins and tables in a public folder. Why that's a problem, and a small custom plugin that stops it.
Read More
vim: tabstop, shiftwidth, softtabstop, expandtab (Explained)
By Charles Joseph · Updated
Four settings decide what the Tab key actually does in Vim. What each one means, with an example .vimrc and where to find it.
Read More
MySQL Essentials: A Guide to Key Commands
By Charles Joseph · Updated
Log in without exposing your password, view and create databases, and more. The MySQL commands worth having at your fingertips.
Read More
How to Change Your WordPress URL in MySQL
By Charles Joseph · Updated
Two rows in wp_options decide where your site lives. The SQL to change them when the admin screen isn't an option.
Read More
How to Enable Promiscuous Mode in VMWare Workstation?
By Charles Joseph · Updated
One line in a .vmx file, nearly impossible to find in the docs. How to turn on promiscuous mode for a VMware network card.
Read More
Understand *NIX Links
By Charles Joseph · Updated
Hard links and symbolic links, shown step by step in an empty directory. How *nix links work, for visual learners.
Read More
How to Get YouTube Thumbnails
By Charles Joseph · Updated
Every YouTube video has thumbnails at several sizes, each at a predictable URL. The list, from 120 by 90 up.
Read More How to Rename a MySQL Database (Step by Step)
By Charles Joseph · Updated
There's no RENAME DATABASE command, so you have to be sneaky. Four steps to rename a MySQL database without losing anything.
Read More
How to Import and Export MySQL Databases
By Charles Joseph · Updated
mysqldump out, mysql in. The command-line steps for backing up and restoring databases and single tables.
Read More
How to Search Your Entire MySQL Database for a Phrase
By Charles Joseph · Updated
One command finds a phrase anywhere in the database, tested on Ubuntu. The command, a breakdown of each part and the output explained.
Read More
How to Reset a WordPress User’s Password From Within MySQL
By Charles Joseph · Updated
Locked out of the admin screen? The wp_users table and one SQL command put you back in.
Read More
How to Use Custom HTTP Headers as Nginx Variables
By Charles Joseph · Updated
Every request header can become a variable in your Nginx config. How the conversion works, and what you can do with it, with an example config.
Read More