Skip to content

Search ThreatNotes

Weekly security intelligence

Everything that broke this week, explained.

A weekly roundup of what actually broke, deep dives into how it worked, and hands-on courses where you try it yourself.

Prefer it by email? One issue a week, free — no sponsors, one-click unsubscribe.

This week's topic

The write-up we think is worth your time right now.

All posts
7 min read

Anatomy of a Credential Stuffing Attack

Credential stuffing is not brute force. Understanding the difference is what makes it detectable — and what makes most rate limits useless against it.

  • credential-stuffing
  • authentication
  • detection

Read the write-up

Latest posts

Deep dives into incidents, tooling, and technique.

View all

Reading Your First Wireshark Capture

Opening a pcap for the first time is overwhelming by design — it shows you everything. Here is the small set of filters and habits that turn noise into a narrative.

  • network
  • wireshark
  • fundamentals
4 min read

Why MFA Fatigue Attacks Work

The failure is not that users are careless. It is that push approval asks a question the user has no way to answer correctly — and asks it dozens of times until they slip.

  • mfa
  • authentication
  • social-engineering
4 min read

Social Engineering Isn’t Just Email

We spent a decade teaching everyone to be suspicious of their inbox. Attackers responded by picking up the phone — where nobody is watching, nobody was trained, and being helpful is literally in the job description.

  • social-engineering
  • human-factors
9 min read

Courses

Hands-on labs and games. Learn the attack by running it.

View all

Intro to Phishing Defense

How phishing actually works, how to spot it under time pressure, and exactly what to do in the first ten minutes after someone clicks.

  • phishing
  • social-engineering
  • fundamentals
1 min read

Weekly news

Curated by hand, every Tuesday.

View all

The software you already trusted

Two browser extensions, a car alarm fitted at the dealership, and WordPress core itself. Almost nothing that went wrong this week came from outside — it came from things that were already installed and already trusted.

  • weekly
  • browser-extensions
  • credential-stuffing
1 min read

Why ThreatNotes

Curated by hand
Every item is read and summarised by a person. No aggregator dumps, no auto-generated filler.
No sponsored content
Nothing is here because a vendor paid for it. If a tool gets mentioned, it is because it worked.
Built to be practical
Write-ups end with what to actually do, and the courses make you do it in a lab.

If that sounds useful, the whole thing fits in one email a week.

See what you'd get