Multi-factor authentication, simply
An extra check when you sign in. Draft lesson outline Describe the difference between a password and an additional authentication factor. Explain that MFA reduces risk but does not make an account…
Making information unreadable without the right key. Draft lesson outline Use a locked-box analogy, then explain its limits: encryption does not automatically make a recipient trustworthy. Try it yourself Add a safe,…
read post →An extra check when you sign in. Draft lesson outline Describe the difference between a password and an additional authentication factor. Explain that MFA reduces risk but does not make an account…
Why unique passwords matter. Draft lesson outline Explain password reuse with a simple key analogy, then introduce password managers. Try it yourself Add a safe, practical exercise here before publishing.
An introduction to messages that pretend to be trustworthy. Draft lesson outline Explain how a message can impersonate a familiar organisation. Use a fictional example and show how to verify the request…
A note on the indicators below: all hostnames and URLs in this post are defanged (hxxps[:]//, [.]) so nothing in the page is clickable. Re-fang them only inside an isolated analysis environment. The detection rules in…
A single spoofed Ledger email, a phishing-tracker pipeline, a vision model that kept us honest and three distinct pieces of attacker infrastructure, two of them still live at time of writing. The…
1. Executive Summary On 2026-08-27 at 14:30 UTC, a UK recipient received a phishing email spoofing an Intuit QuickBooks payment notification. The email claimed a payment had been deposited and invited the recipient to…