Everyone has heard the word. Far fewer can say what a phishing email is actually trying to get out of them, or why the good ones look nothing like the examples in your annual training.
Phishing is any message engineered to make you act against your own interest: hand over a password, approve a login, open a file, pay an invoice. It's not a technical attack, it's a social one that happens to arrive by email. Nobody is breaking your inbox; they are borrowing your habits.
Real names, real programs, real contract numbers. Pulled from public sites and a partner’s stolen mail.
A reply in a thread you started, or a mailbox that really does belong to your supplier. Filters see a friend.
Do something now, quietly, outside how you normally do it. Urgency plus a shortcut around process.
A wire in the wrong account, a session token, or remote access that outlives the email.
The badly spelled version still exists, and it is not what we worry about. The good ones are polished, in-thread, and specific to your program.
Which is why “we have a filter” is not a plan: a reply inside an existing conversation almost never gets flagged.
One message. One click. One decision you get to make slowly.
Phishing is still how most intrusions start, and defense suppliers are a deliberate target: the same program data a prime protects sits in the inboxes of far smaller companies. Attackers go where the trust is real and the tooling is thinner.
You are not expected to spot every fake, and we are not grading you. Slow down on the ask, flag the ones that feel off. Filters catch strangers; people and analysts catch the mail that shows up already trusted.
A crude wiper erased the hard drives of most of Saudi Aramco’s office fleet in hours. The malware wasn’t sophisticated. The flat network was.
Maya's security career began during her CS undergrad at CU Boulder and has spanned contracting at Microsoft and running cybersecurity for MSPs. Four years writing for Her Campus means she came into security already knowing how to tell a story.
A Girl Security alum, WiCyS member, and CTF designer, she believes the best defenders come from everywhere. RADICL's focus on the underserved Defense Industrial Base fits her passion for SMB security: the segment that gets overlooked, underprotected, and increasingly targeted by nation-states.
"The companies that get hit hardest are the ones everyone assumes are too small to be a target." — Maya Douglas, SOC Analyst II · vSOC
A first-seen hardware-inventory query on a developer workstation paged as suspicious recon. Full process ancestry showed a battery-health check from an IDE terminal. Closed benign, and we tuned the rule so it stops firing.
A file disguised as a routine coursework template hit a learning platform’s upload pipeline carrying a hash reputation already flagged as a known web shell. We traced its process lifecycle and confirmed it never executed.
A file posing as a .NET Framework installer silently deployed a foreign consumer antivirus suite plus a driver with known vulnerabilities. The driver was quarantined on install; we flagged the rest for removal.
A rogue “Delta WiFi Fast” network appeared on Flight 591 out of Las Vegas the day after DEF CON. Crew killed in-flight Wi-Fi for 30 minutes and the feds are investigating. Classic evil twin: a network that looks like the one you expected, run by someone who wants your session. Same lure as email phishing, different delivery.
Researchers hid one-pixel text on a web page that made an AI coding assistant rewrite its own config and launch an attacker-controlled server with developer privileges. Nobody clicked anything. It is patched, but the pattern is the story: an agent that reads the web will read instructions planted there too.
A new executive order pushes end-to-end visibility into defense supply chains: software dependencies, foreign ownership, supplier risk. Expect the questions to reach subcontractors long before any rule does, and expect primes to ask for answers in writing.
If a download or install prompt surprises you, don’t click through and don’t just dismiss it. Report it. A 10-second heads-up lets us check whether it was a real attempt before the next one lands, and a dismissed prompt tells us nothing.
Prefer this newsletter as a PDF? Download it here.