Experts share their insights on protecting against cyber threats and staying ahead of evolving security risks.
Recently active
In January 2026, George Skaff outlined several trends expected to shape the cybersecurity landscape for SMBs throughout the year.SVP of Cybersecurity SMB at OpenTextRather than predicting specific malware families or threat actors, the focus was on broader shifts in attacker behavior, including AI-driven phishing, deepfake-enabled fraud, supply chain compromises, and the growing challenge of defending organizations with limited security resources.Five months later, many of those trends have become everyday realities. Prediction #1: AI-Powered Social Engineering Would AccelerateGeorge warned that AI would allow attackers to create more convincing phishing campaigns at greater scale.Since January, AI-assisted phishing campaigns and social engineering attacks have continued to evolve. Threat groups such as Scattered Spider have demonstrated how attackers can successfully target organizations through identity-focused attacks and social engineering rather than relying on sophisticated malwa
Every year, World Password Day brings the same advice:Use strong passwords. Don’t reuse them. Enable MFA.That guidance isn’t wrong. It’s just no longer enough.Attackers aren’t trying to “hack” passwords anymore.They’re logging in with them. Attackers Aren’t Breaking In. They’re Logging In. The threat landscape has shifted from brute force to credential theft and abuse at scale.Phishing kits are cheap and highly effective.Infostealers are pulling credentials and session tokens at scale.Session tokens and cookies can bypass traditional MFA.Phishing activity alone has surged over 200% year-over-year, increasingly tied to credential capture instead of malware delivery.Valid credentials are now one of the most reliable, low-effort entry points into organizations. The Password Problem Isn’t Strength. It’s Exposure. Users can create complex passwords and still get compromised because those credentials get:Phished Reused across services Harvested by malware on infected endpoints Captured along
March 31 is World Backup Day. It’s a good reminder, but the conversation around backup hasn’t kept pace with how attacks actually happen today. For years, the message was simple: back up your data so you can recover it.That is still true, but in 2026 that is simply not enough. Today’s attackers do not just delete data. They steal it, encrypt it, threaten it, and monetize it. Backup is still critical, but backup alone is no longer enough, and that is where a lot of organizations get caught off guard. More importantly, backup is no longer something you think about once a year. It needs to be continuous, tested, and treated as part of everyday security operations. The Reality: Ransomware Has Evolved Beyond RecoveryModern ransomware attacks rarely stop at encryption.Attackers now: Exfiltrate sensitive data before encrypting it Threaten public leaks to pressure payment Target backups directly to eliminate recovery options Exploit identity systems to maintain persistence This means eve
Change Your Password Day is February 1, which makes it a good moment to pause and do a quick gut check on account security.That said, simply changing passwords on a schedule is not the silver bullet it once was. Where we are in 2026:• Stop reusing passwords across work and personal accounts• Use a password manager if possible to generate long, unique passwords• Turn on MFA everywhere it’s available• Pay special attention to email, VPN, cloud, and identity accounts 💡 My personal recommendation: use passphrasesIf you’re creating a password yourself, long passphrases are far more effective and easier to remember than short “complex” passwords.For example:snow white and the seven dwarvesWhy this works: Length matters more than special characters It’s easier for humans to remember Spaces count as characters if the system allows them Long phrases dramatically increase resistance to brute-force attacks (Use this as a pattern, not the exact phrase. Avoid anything famous or searchable.)
As tax season approaches, individuals and businesses alike are looking for ways to maximize deductions, upgrade technology, and stay compliant with evolving regulations. However, tax season is also prime time for cybercriminals, who exploit the chaos with phishing scams, malware attacks, and data theft.This year, whether you’re a small business upgrading IT infrastructure or an individual filing taxes online, security should be at the forefront of your financial planning. SMBs: Cybersecurity Considerations When Writing Off Old Equipment Writing Off IT Equipment: Tax Benefits & Security RisksTax season is an opportunity for SMBs to write off depreciated IT assets and invest in new technology, leveraging Section 179 deductions to offset costs. However, replacing outdated hardware without a proper cybersecurity strategy can leave businesses exposed to threats. Security Risks When Disposing of Old Equipment: Data Residue on Retired Devices – Hard drives, SSDs, and networked storage ma
The UK government’s push to weaken Apple’s encryption isn’t just a bad idea, it’s a global security failure waiting to happen. By demanding that Apple build access into its secure systems, Britain is setting a dangerous precedent that will absolutely be exploited by cybercriminals, hostile nations, and rogue insiders. History shows that governments are incapable of keeping sensitive data secure as their own databases have been breached countless times. If Apple or any tech giant opens the door for government access, it’s only a matter of time before that door is blown wide open for hackers everywhere. UK’s Dangerous Legislation to Undermine Encryption The UK’s Investigatory Powers Act (IPA) 2016 and the Online Safety Bill (OSB) 2023 give the government sweeping authority to demand access to encrypted communications. The IPA allows secret government orders (Technical Capability Notices) forcing companies like Apple to weaken security measures. The OSB, while framed as protecting childre
What Are Passkeys? You may have seen the term "passkeys" appearing more frequently in tech news, app updates, and security discussions. Major companies like Apple, Google, and Microsoft are rolling out passkeys as a replacement for passwords, promising both enhanced security and a smoother user experience. But what exactly are passkeys, and why are they considered the future of authentication?With Password Day coming up this Saturday, it's the perfect time to discuss the future of authentication. Passwords have long been the foundation of online security, but they come with significant downsides: they can be stolen, guessed, or reused across multiple sites. Enter passkeys, a next-generation authentication technology designed to replace passwords entirely with a more secure and user-friendly alternative.Passkeys leverage public-key cryptography to authenticate users without requiring them to remember or type in a password. Instead, passkeys are stored on a trusted device (like your phon
Valentine’s Day may be around the corner, but not all love stories have happy endings, especially when artificial intelligence (AI) gets involved. Scammers have evolved, using AI-generated romance scams to prey on emotions, steal money, and manipulate victims. From fake AI girlfriends to deepfake-powered romance scams, digital deception is at an all-time high. The Rise of AI-Powered Romance ScamsTraditionally, romance scams involved con artists posing as potential love interests to build emotional connections before requesting financial assistance. But today, AI has taken fraud to the next level. Deepfake Identities: Scammers now use AI to create hyper-realistic fake photos and videos to impersonate real people. AI Chatbots for Romance: Some platforms allow fraudsters to automate interactions with victims, keeping them emotionally engaged 24/7. Voice Cloning Scams: AI-generated voices can mimic real individuals, making phone conversations feel authentic. One shocking example is the
Consumers in 2025 will face a threat landscape that blends sophisticated technology with highly personalized tactics. Your home, devices, and personal information will be prize targets for adversaries who deploy advanced AI and social engineering techniques. Predictions for Consumers in 2025 1. Ransomware Evolves into ‘Home Hostage’ ScenariosAs more consumers rely on smart homes, threat actors will try holding connected devices, stored data or the entire home network “hostage.” While traditional ransomware focuses on data encryption, future attacks might threaten to disable critical IoT systems or leak sensitive personal content unless a ransom is paid. 2. Hyper-Targeted Phishing Through AI AvatarsConsumers will face a new era of phishing attacks delivered via realistic AI-generated voices or deepfake videos purporting to be friends, family members, or trusted brands. Traditional “spoofed” emails will give way to convincing real-time communications that erode the line between legitima
As 2025 is in full swing, cybersecurity continues to evolve with new threats and technologies. Drawing from recent trends, expert analyses, and my previous insights in "The Nastiest Malware 2024," here's a look at what small to medium-sized businesses (SMBs) can expect in the cybersecurity landscape, particularly concerning ransomware, phishing, AI, and other typical cyber threats. Predictions 1. Ransomware’s attacks on SMB will grow to be a larger share of the pieRansomware operators, who’ve historically had a focus on large enterprises, are expected to increasingly pivot toward SMBs by 2025. These “breadth attacks” rely on automated toolsets that can rapidly compromise a broader pool of smaller targets. SMBs, often with limited cybersecurity budgets and reactive security measures, will be viewed as low-hanging fruit. 2. AI-Augmented Threat Campaigns Against SMB ToolingAI-powered malware and phishing kits will become more cost-effective for adversaries, enabling them to generate cust
Brute force attacks stand as a testament to the idea that persistence often pays off - unfortunately, in this context, it’s for bad actors. This blog dives into the mechanics of brute force attacks, unraveling their methodology and focusing on their application. Whether its Remote Desktop Protocol (RDP), or direct finance theft, brute force attacks are a prime tactic in the current cybersecurity landscape. What is a Brute Force Attack?A brute force attack is a cyber attack method where an attacker attempts to gain unauthorized access to a system or data by systematically trying every possible combination of passwords or keys. This method relies on the sheer power of repetition and the computational capacity to try thousands, if not millions, of combinations in a short span of time. Think of it as trying every key on a keyring until finding the one that unlocks a door.Types of Brute Force AttacksSimple brute force attacks: This basic approach involves trying all possible combinations o
OpenText is committed to providing you with the latest intelligence and tips to safeguard your digital life, especially during high-risk periods like tax season. Our threat analysts are constantly monitor the ebb and flow of various threats. One trend that has recently caught our attention is the notable spike in malware-infected cracked software, particularly as we enter tax season. This post aims to shed light on the dangers of using cracked software, share best practices for a secure tax season, and highlight our latest intelligence on the surge in cracked tax software threats. The Hidden Cost of Cracked Software Cracked software, often touted as a cost-free way to access games and expensive software, carries a significant risk far beyond legal and ethical concerns. These unauthorized versions are frequently loaded with malware, from trojans and keyloggers to ransomware. The allure of free access blinds users to the dangers, turning their devices into gateways for cybercriminals to
In today's digital age, Artificial Intelligence (AI) is advancing at an astonishing pace, posing new challenges to the integrity of biometric security. The advent of AI-driven tools, capable of crafting deepfakes, exposes a significant flaw in biometric authentication systems: unlike passwords, biometric identifiers cannot simply be reset once they are compromised.The emergence of the "GoldPickaxe" malware, attributed to a group fluent in Chinese, serves as a vivid illustration of AI's potential to circumvent biometric protections. By deceiving individuals into submitting facial scans under the pretense of a legitimate service, the perpetrators utilize deepfake technology to gain unauthorized access to the victims' financial accounts. This scenario underscores the urgent need for industries, particularly banking, to rapidly adjust to these evolving cybersecurity threats. For a detailed technical analysis and to learn more about the indicators of compromise associated with GoldPickaxe,
In the digital age, the quest for love has moved online, but so have the fraudsters, with romance scams reaching record highs. These scams don't just harm individuals financially and emotionally; they can also pose significant risks to businesses. Let's explore how these scams work, their impact, and how both businesses and consumers can protect themselves. Understanding Romance ScamsRomance scams involve fraudsters creating fake profiles on dating sites, social media platforms, or apps to establish relationships with victims, gain their trust, and eventually, scam them out of money. In 2022, nearly 70,000 people reported such scams, with losses totaling a staggering $1.3 billion. The median loss per victim was around $4,400, highlighting the severe impact on individuals. Key Trends to WatchThe reported losses to romance scams were up nearly 80% year over year, showing a rapid increase in both the frequency and effectiveness of these scams. This trend underscores the evolving threa
The Internet of Things (IoT) has revolutionized how we interact with our surroundings, making life more convenient and efficient. IoT devices connect everyday objects to the internet, allowing us to control our homes, monitor our health, and even track our belongings. However, this interconnectivity comes at a cost: the exponential growth of IoT devices has led to increased cybersecurity risks. In this article, we will discuss trends in IoT and their implications on the cybersecurity landscape, and ponder whether the convenience provided by IoT is worth the security trade-offs. The concept of IoT can be traced back to the 1980s, but it wasn't until the early 2000s that IoT devices began to gain widespread adoption. In the early days of IoT, security was often an afterthought and the focus was on getting a working product out the door. However, as IoT devices have proliferated, the risks associated with their widespread use have become more apparent.I was at a Defcon event about a decad
Artificial intelligence (AI) and machine learning (ML) are going to revolutionize the field of cybersecurity. These technologies can be used to improve the detection and prevention of cyber threats, making it easier for organizations to protect their networks and data. However, as with any new technology, there are also potential risks and challenges that must be considered.One of the biggest benefits of AI and ML in cybersecurity is their ability to automatically detect and respond to cyber threats. These technologies can be used to analyze large amounts of data, such as network traffic logs and characteristics of files to identify patterns and anomalies that may indicate a cyber attack or malicious nature. They can also be used to automatically respond to threats, such as by shutting down a compromised system or blocking a malicious IP address. Additionally, the benefits of AI and ML in cybersecurity is their ability to improve the efficiency and effectiveness of incident response. T
Welcome to Data Privacy Week! This is an annual campaign with the purpose of spreading awareness about online privacy and educating citizens on how to manage their personal information and keep it secure. Today we will discuss the importance of using cold storage password managers as well as the impact of the General Data Protection Regulation (GDPR) on data privacy. Get ready to learn about personal data security, creating and storing strong passwords as well as the negative side-effects of rising GDPR fines. Password Manager Data Breaches At the end of 2022, Norton LifeLock suffered a data breach. Symantec reports that their systems were not directly compromised - it seems as though the attackers used a technique called credential stuffing to try out user credentials for the service in bulk. It is likely that the attacker bought a large amount of stolen user credentials on the Dark Web. By attempting logins with that massive list of credentials, the attacker was successful in comprom
Zero Trust is a security approach that has gained significant attention in the cybersecurity world in recent years. But what is Zero Trust, and how effective is it in protecting against cyber threats? Cybersecurity professionals are rightfully skeptical of phrases that suddenly become buzzwords overnight. However, there are many legitimate technologies and policies that fall under the umbrella term “Zero Trust”. In this post, we will explore the concepts and technologies involved in Zero Trust and attempt to differentiate marketing hype from factual evidence. DefinitionFirst, let’s define zero trust. At its core, Zero Trust is a security model that assumes all users and devices within a network are untrusted and potentially malicious. This means that, rather than relying on the traditional perimeter-based security model which assumes that everything inside the network is trusted, a Zero Trust approach treats all access requests as coming from an untrusted source. There are a few other
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.