Skip to content

Search ThreatNotes

The archive

Posts

Long-form write-ups on incidents, tooling, and technique — how the attack actually worked, what the telemetry looked like, and what to do about it.

9 write-ups19 topicsNew post most weeks
Newest7 min read

Anatomy of a Credential Stuffing Attack

Credential stuffing is not brute force. Understanding the difference is what makes it detectable — and what makes most rate limits useless against it.

  • credential-stuffing
  • authentication
  • detection

Read the write-up

Reading Your First Wireshark Capture

Opening a pcap for the first time is overwhelming by design — it shows you everything. Here is the small set of filters and habits that turn noise into a narrative.

  • network
  • wireshark
  • fundamentals
4 min read

Why MFA Fatigue Attacks Work

The failure is not that users are careless. It is that push approval asks a question the user has no way to answer correctly — and asks it dozens of times until they slip.

  • mfa
  • authentication
  • social-engineering
4 min read

Social Engineering Isn’t Just Email

We spent a decade teaching everyone to be suspicious of their inbox. Attackers responded by picking up the phone — where nobody is watching, nobody was trained, and being helpful is literally in the job description.

  • social-engineering
  • human-factors
9 min read

Public Wi-Fi: What’s Actually At Risk

The scary version of this advice is fifteen years out of date. Here is what someone on the café network can genuinely do to you in 2026 — and the two things that still go badly wrong, neither of which encryption can save you from.

  • wifi
  • network-security
9 min read

The Lock Icon Doesn’t Mean “Safe”

The padlock is an armoured van. It guarantees nobody read your letter on the way — and has no opinion whatsoever about whether the person you posted it to is a con artist.

  • https
  • tls
  • web-basics
8 min read

What MFA Actually Protects You Against

MFA is either “a magic switch that ends hacking” or “already broken, why bother”, depending on who you ask. Both are wrong. Here is the honest version — what it kills stone dead, what walks straight past it, and which kind to actually turn on.

  • mfa
  • authentication
9 min read

Anatomy of a Phishing Email

Stop trying to sense whether an email “feels off”. A phishing message has five jobs it must do to work, and every one of them leaves a mark you can check in about eight seconds.

  • phishing
  • social-engineering
  • email-security
8 min read

Why Your Password Isn’t the Problem (Reuse Is)

You have been trained to worry about whether your password is strong enough. Almost nobody is attacked that way. Here is the thing that actually loses people their accounts — explained with a shed, a locksmith, and some uncomfortable arithmetic.

  • passwords
  • credential-reuse
  • basics
9 min read