Signal & Noise, Volume 6
by Maya Douglas on Aug 14, 2026
Field Guide: What Is Phishing, Really?
Everyone has heard the word. Far fewer can say what a phishing email is actually trying to get out of them, or why the good ones look nothing like the examples in your annual training.
Phishing is any message engineered to make you act against your own interest: hand over a password, approve a login, open a file, pay an invoice. It's not a technical attack, it's a social one that happens to arrive by email. Nobody is breaking your inbox; they are borrowing your habits.
How a Phishing Attack Actually Runs
01 — Recon
Real names, real programs, real contract numbers. Pulled from public sites and a partner’s stolen mail.
02 — Trust
A reply in a thread you started, or a mailbox that really does belong to your supplier. Filters see a friend.
03 — The ask
Do something now, quietly, outside how you normally do it. Urgency plus a shortcut around process.
04 — Payoff
A wire in the wrong account, a session token, or remote access that outlives the email.
Stop hunting for typos
The badly spelled version still exists, and it is not what we worry about. The good ones are polished, in-thread, and specific to your program.
Which is why “we have a filter” is not a plan: a reply inside an existing conversation almost never gets flagged.
Do this instead: S.T.A.R.
- Stop. Urgency is the attack. Nothing legitimate dies in five minutes.
- Think about the ask. Payment change, password, approval, install?
- Ask on another channel. Call the person. Never verify by reply.
- Report it while it is still a question. Especially if you clicked.
One message. One click. One decision you get to make slowly.
Anatomy of the ask
- Credential harvest — a login page reached by link, not bookmark, collecting your password
- MFA fatigue — repeat approval prompts you never triggered
- Thread hijack — a reply inside a real conversation you started
- Payment redirect — new bank details on a familiar invoice
- Silent install — an attachment that runs remote-access software
Why this matters
Phishing is still how most intrusions start, and defense suppliers are a deliberate target: the same program data a prime protects sits in the inboxes of far smaller companies. Attackers go where the trust is real and the tooling is thinner.
You are not expected to spot every fake, and we are not grading you. Slow down on the ask, flag the ones that feel off. Filters catch strangers; people and analysts catch the mail that shows up already trusted.
This Week in Cyber History
Aug 15, 2012 — Shamoon Wipes 30,000 Workstations
A crude wiper erased the hard drives of most of Saudi Aramco’s office fleet in hours. The malware wasn’t sophisticated. The flat network was.
Meet the Analyst
Maya Douglas — SOC Analyst II
Maya's security career began during her CS undergrad at CU Boulder and has spanned contracting at Microsoft and running cybersecurity for MSPs. Four years writing for Her Campus means she came into security already knowing how to tell a story.
A Girl Security alum, WiCyS member, and CTF designer, she believes the best defenders come from everywhere. RADICL's focus on the underserved Defense Industrial Base fits her passion for SMB security: the segment that gets overlooked, underprotected, and increasingly targeted by nation-states.
"The companies that get hit hardest are the ones everyone assumes are too small to be a target." — Maya Douglas, SOC Analyst II · vSOC
Case Spotlight
Benign · rule tuned
A first-seen hardware-inventory query on a developer workstation paged as suspicious recon. Full process ancestry showed a battery-health check from an IDE terminal. Closed benign, and we tuned the rule so it stops firing.
Never executed
A file disguised as a routine coursework template hit a learning platform’s upload pipeline carrying a hash reputation already flagged as a known web shell. We traced its process lifecycle and confirmed it never executed.
Driver quarantined
A file posing as a .NET Framework installer silently deployed a foreign consumer antivirus suite plus a driver with known vulnerabilities. The driver was quarantined on install; we flagged the rest for removal.
Eye on the Threatscape
01 — Evil Twin at 30,000 Feet, Post-DEF CON
A rogue “Delta WiFi Fast” network appeared on Flight 591 out of Las Vegas the day after DEF CON. Crew killed in-flight Wi-Fi for 30 minutes and the feds are investigating. Classic evil twin: a network that looks like the one you expected, run by someone who wants your session. Same lure as email phishing, different delivery.
02 — One Invisible Pixel, Full Dev Access
Researchers hid one-pixel text on a web page that made an AI coding assistant rewrite its own config and launch an attacker-controlled server with developer privileges. Nobody clicked anything. It is patched, but the pattern is the story: an agent that reads the web will read instructions planted there too.
03 — Know Every Supplier In Your Software
A new executive order pushes end-to-end visibility into defense supply chains: software dependencies, foreign ownership, supplier risk. Expect the questions to reach subcontractors long before any rule does, and expect primes to ask for answers in writing.
vSOC Tip of the Week
If a download or install prompt surprises you, don’t click through and don’t just dismiss it. Report it. A 10-second heads-up lets us check whether it was a real attempt before the next one lands, and a dismissed prompt tells us nothing.
Prefer this newsletter as a PDF? Download it here.
- DIB Innovators (128)
- Podcast (127)
- Industry Analysis (104)
- Threat Hunting and Intelligence (28)
- Regulatory Compliance (24)
- Attack Surface and Vulnerability Management (15)
- CMMC (14)
- Zero Gravity Summit (11)
- General (6)
- Signal & Noise (6)
- Company (5)
- Security Operations & vSOC (5)
- Testimonials (5)
- Founder (4)
- Incident Response (3)
- Managed Security Operations (3)
- Operational Resilience (2)
- Threat Management (1)
- Webinar (1)
You May Also Like
These Related Stories

Signal & Noise, Volume 2

SOC Alert Triage in Cybersecurity: Guide to Incident Response


No Comments Yet
Let us know what you think