Section

Malware And Phishing

Guides, explainers, and practical reads updated regularly.

All Articles
MALWARE AND PHISHING
Perfect spelling is no longer a sign that an email is genuine
CISA now states plainly that some phishing emails have perfect grammar and spelling. Here are the signs that survived, and the one check that still…
Hands resting on a laptop keyboard in front of a red screen reading that the user's personal files have been encrypted
MALWARE AND PHISHING
How a phishing email turns into malware on your machine
The pretext, the click, the symptoms and the clean-up — the sequence as the FTC and CISA describe it, with the three places to report…
A security software dashboard divided into Security, Privacy and Performance columns, with green ticks and amber warnings
MALWARE AND PHISHING
Staff ransomware training versus the controls that do the work
Training helps at the margins. The #StopRansomware Guide names three technical controls first, and here is how to run both without confusing them.
A group of employees with lanyards sitting in rows at a training session, one of them speaking
MALWARE AND PHISHING
How to check a link or attachment before you open it
Hovering over a link is not enough, and a padlock proves nothing. The checks CISA and the FBI actually recommend, in the order to do…
An illustration of an email inbox with a red Compose button and an unread count of several thousand messages
MALWARE AND PHISHING
What phishing awareness training can and cannot change
No agency publishes a figure for how much training reduces real compromise. Here is what it plausibly does, and the controls that do not depend…
Employees seated around tables in a small meeting room during a training session, with a whiteboard at the front
MALWARE AND PHISHING
Signs a message carries malware, and signs it already ran
Two different lists: the indicators in the message itself, and the FTC's symptoms of a device that is already infected.
Envelope icons floating in the air above a dark surface, suggesting incoming email
MALWARE AND PHISHING
What ransomware recovery actually involves, step by step
The documented sequence: isolate, report, restore from offline backups, rebuild if needed — and why the FBI does not support paying.
Hands typing on a laptop on a wooden desk, with a stethoscope lying beside it
MALWARE AND PHISHING
Three checks that settle whether an email is real
A short, repeatable routine for suspicious messages: check the ask, check the address, then verify on a channel the sender did not choose.
Three padlocks of different sizes on a surface lit from one side in red and the other in green