<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>ThreatNotes</title><description>Cybersecurity writing, courses, and a weekly roundup of what actually mattered.</description><link>https://threatnotes.org/</link><language>en</language><item><title>The software you already trusted</title><link>https://threatnotes.org/news/2026-07-20/</link><guid isPermaLink="true">https://threatnotes.org/news/2026-07-20/</guid><description>Two browser extensions, a car alarm fitted at the dealership, and WordPress core itself. Almost nothing that went wrong this week came from outside — it came from things that were already installed and already trusted.</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate><category>weekly</category><category>browser-extensions</category><category>credential-stuffing</category><category>ransomware</category><category>wordpress</category></item><item><title>Anatomy of a Credential Stuffing Attack</title><link>https://threatnotes.org/posts/anatomy-of-a-credential-stuffing-attack/</link><guid isPermaLink="true">https://threatnotes.org/posts/anatomy-of-a-credential-stuffing-attack/</guid><description>Credential stuffing is not brute force. Understanding the difference is what makes it detectable — and what makes most rate limits useless against it.</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>credential-stuffing</category><category>authentication</category><category>detection</category></item><item><title>Reading Your First Wireshark Capture</title><link>https://threatnotes.org/posts/reading-your-first-wireshark-capture/</link><guid isPermaLink="true">https://threatnotes.org/posts/reading-your-first-wireshark-capture/</guid><description>Opening a pcap for the first time is overwhelming by design — it shows you everything. Here is the small set of filters and habits that turn noise into a narrative.</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>network</category><category>wireshark</category><category>fundamentals</category></item><item><title>Why MFA Fatigue Attacks Work</title><link>https://threatnotes.org/posts/why-mfa-fatigue-attacks-work/</link><guid isPermaLink="true">https://threatnotes.org/posts/why-mfa-fatigue-attacks-work/</guid><description>The failure is not that users are careless. It is that push approval asks a question the user has no way to answer correctly — and asks it dozens of times until they slip.</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate><category>mfa</category><category>authentication</category><category>social-engineering</category></item><item><title>Social Engineering Isn’t Just Email</title><link>https://threatnotes.org/posts/social-engineering-isnt-just-email/</link><guid isPermaLink="true">https://threatnotes.org/posts/social-engineering-isnt-just-email/</guid><description>We spent a decade teaching everyone to be suspicious of their inbox. Attackers responded by picking up the phone — where nobody is watching, nobody was trained, and being helpful is literally in the job description.</description><pubDate>Mon, 09 Feb 2026 00:00:00 GMT</pubDate><category>social-engineering</category><category>human-factors</category></item><item><title>Public Wi-Fi: What’s Actually At Risk</title><link>https://threatnotes.org/posts/public-wifi-whats-actually-at-risk/</link><guid isPermaLink="true">https://threatnotes.org/posts/public-wifi-whats-actually-at-risk/</guid><description>The scary version of this advice is fifteen years out of date. Here is what someone on the café network can genuinely do to you in 2026 — and the two things that still go badly wrong, neither of which encryption can save you from.</description><pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate><category>wifi</category><category>network-security</category></item><item><title>The Lock Icon Doesn’t Mean “Safe”</title><link>https://threatnotes.org/posts/the-lock-icon-doesnt-mean-safe/</link><guid isPermaLink="true">https://threatnotes.org/posts/the-lock-icon-doesnt-mean-safe/</guid><description>The padlock is an armoured van. It guarantees nobody read your letter on the way — and has no opinion whatsoever about whether the person you posted it to is a con artist.</description><pubDate>Mon, 26 Jan 2026 00:00:00 GMT</pubDate><category>https</category><category>tls</category><category>web-basics</category></item><item><title>What MFA Actually Protects You Against</title><link>https://threatnotes.org/posts/what-mfa-actually-protects-you-against/</link><guid isPermaLink="true">https://threatnotes.org/posts/what-mfa-actually-protects-you-against/</guid><description>MFA is either “a magic switch that ends hacking” or “already broken, why bother”, depending on who you ask. Both are wrong. Here is the honest version — what it kills stone dead, what walks straight past it, and which kind to actually turn on.</description><pubDate>Mon, 19 Jan 2026 00:00:00 GMT</pubDate><category>mfa</category><category>authentication</category></item><item><title>Anatomy of a Phishing Email</title><link>https://threatnotes.org/posts/anatomy-of-a-phishing-email/</link><guid isPermaLink="true">https://threatnotes.org/posts/anatomy-of-a-phishing-email/</guid><description>Stop trying to sense whether an email “feels off”. A phishing message has five jobs it must do to work, and every one of them leaves a mark you can check in about eight seconds.</description><pubDate>Mon, 12 Jan 2026 00:00:00 GMT</pubDate><category>phishing</category><category>social-engineering</category><category>email-security</category></item><item><title>Why Your Password Isn’t the Problem (Reuse Is)</title><link>https://threatnotes.org/posts/why-your-password-isnt-the-problem/</link><guid isPermaLink="true">https://threatnotes.org/posts/why-your-password-isnt-the-problem/</guid><description>You have been trained to worry about whether your password is strong enough. Almost nobody is attacked that way. Here is the thing that actually loses people their accounts — explained with a shed, a locksmith, and some uncomfortable arithmetic.</description><pubDate>Mon, 05 Jan 2026 00:00:00 GMT</pubDate><category>passwords</category><category>credential-reuse</category><category>basics</category></item></channel></rss>