> articles
Articles
Writing about how systems are attacked and how they are built, in plain terms. No vendor language, no scare stories — just the mechanics, and what they mean for what you should actually do.
How a phishing attack is actually built
Most phishing advice is useless because it describes the symptoms. Here is the construction, from the attacker's side — and the two defences that actually survive it.
What happens to your password after a breach
Follow one password from a leaked database to somebody else's account being taken over. The mechanics explain why reuse is the only fact that matters.
What an attacker learns about you before touching anything
Before anyone touches a system they read what you already published. Certificate logs, job adverts, document metadata. Here is how to audit your own exposure the same way.
Now check your own
Reading about how systems come apart is useful. Watching it happen to yours is more useful. Describe what you have built and the tool will run the same first pass on it.