Posts

OSINT (Open-Source Intelligence)

Image
  We all like to post online to show what we’re up to so others can see — for example, vacation pictures. But all this can give strangers a lot of information about us. OSINT (Open-Source Intelligence) is the process of collecting information that is already public. Hackers can use OSINT to: Guess your passwords. Find out where you live or work. Know when you are not home. Send fake messages that look real. Examples of oversharing that can put you at risk: Posting a picture of your car with the license plate visible. Sharing your pet’s name (often used in passwords). Announcing travel plans before you go. Posting photos with work ID badges in the background. How to stay safe: Check and update your privacy settings regularly. Don’t post your location in real time. Keep birthdays, phone numbers, and addresses private. Use strong passwords that don’t include personal details. Remember: Once you post something online, it can stay there fo...

St. Paul Cyberattack

Image
  Hi everyone!  Welcome back to Cyber Secure Weekly Blog . This week, we’re talking about something big that happened right here in Minnesota  a real cyberattack on the City of St. Paul . What Happened? In late July 2025, the city of St. Paul was hit by a cyberattack. Hackers broke into the city’s computer systems. It wasn’t just a glitch — it was a serious attack by people who knew what they were doing. To protect the city, officials had to shut down internet, emails, and Wi-Fi in city buildings like libraries and offices. City workers had to go back to pen and paper! Who Responded? Because this attack was so serious, the Minnesota National Guard’s cyber team was called in. This is the first time they’ve been used like this inside the state. The FBI and FEMA are also helping investigate. The goal: find out who did this and make sure it doesn’t happen again. What Services Were Affected?  Public Wi-Fi stopped working City employees couldn’t access emails or sys...

TEAP App Hack — What Happened and How to Stay Safe

Image
  Hi everyone! 👋 This week’s post is about a serious cybersecurity issue involving a fast-growing women-only app called TEA (also known as the TEAP app ). If you've seen it in the news lately, it's because of a major data breach that affected tens of thousands of users. Let's break down what the TEAP app is, what happened during the hack, and what steps you can take to protect yourself. What is the TEAP App? The TEA app is a private, women-only platform where users can anonymously review and share information about men especially for dating safety. Think of it like a “Yelp for exes” or a modern version of the whisper network. What Happened? Recently, hackers found a way to break into TEAP’s system. This allowed them to access users’ personal information such as names, email addresses, and possibly more sensitive data. The breach caused a lot of worry because it can lead to identity theft or fraud if that information falls into the wrong hands. How Did the Hack Hap...

🧠 Deepfakes: What They Are and Why We All Need to Pay Attention

Image
  👋 Hello and Welcome! As technology grows, so do the risks we face online. One of the biggest and fastest-growing threats in 2025 is something called a deepfake  and it’s more than just a funny video. It’s a serious cybersecurity concern that affects all of us. In this blog, I’ll explain what deepfakes are, how they work, and why we need to protect ourselves from them.  🤖 What Is a Deepfake? A deepfake is a video, audio, or image that has been changed using artificial intelligence (AI) to look or sound real — but it’s completely fake. For example: A video might show a person saying something they never actually said. A voice recording could sound exactly like your friend or boss — but it’s not really them. Deepfakes are made to trick people , and today, they’re more realistic than ever. 🛠 How Do Deepfakes Work? Deepfakes are created using a type of AI called deep learning . Computers study real pictures, videos, and voices of a person, and then use that...

Insider Threats: Why Who You Hire Matters for Cybersecurit

Image
  In 2024, something surprising happened at a cybersecurity company called KnowBe4. They almost hired a person who turned out to be a hacker from North Korea. Luckily, they found out before the person started working there. This shows us an important lesson: not all hackers attack from outside a company. Sometimes, the threat comes from people inside the company . These can be workers who want to cause harm, or even people hired by other countries trying to steal secrets or cause problems. Why Is This a Big Deal? Some countries try to sneak their hackers into important companies by hiring them as employees. These “insider threats” are very dangerous because once inside, they have more access to sensitive information and systems. Experts say companies must be very careful during hiring and must keep watching their workers to catch any suspicious actions. What Can Companies Do to Stay Safe? Check carefully before hiring anyone, especially for important jobs like IT or securit...

Multi-Factor Authentication – A Simple Step That Stops Hackers

  Article Topic : “Why MFA (Multi-Factor Authentication) is No Longer Optional” This week, I explored a short but important article from the Cybersecurity & Infrastructure Security Agency (CISA) about Multi-Factor Authentication (MFA). 🔗 Read the article here  What is MFA? Multi-Factor Authentication means using more than one method to log into your account like a password plus a code sent to your phone. It adds an extra layer of security even if your password is stolen. Key Points I Learned: MFA blocks 99% of automated attacks It's now available on most major platforms like Google, Apple, and banks Cybercriminals rely on stolen passwords, but MFA stops them My Reflection: This article helped me understand how simple but powerful Multi-Factor Authentication (MFA) really is when it comes to protecting accounts. Before reading it, I assumed that having a strong password was enough to keep my information safe. But now I realize that even strong passwords can b...

IoT boosts the Shadow IT threat

 This week, I read a fascinating article about how the Internet of Things (IoT) is making it harder for companies to control what’s connected to their networks introducing serious Shadow IT risks . Shadow IT refers to the use of technology (like apps, software, or devices) without the knowledge or approval of the IT department. Many people bring their own smart devices to work such as smartwatches, fitness trackers, or smart speakers and connect them to the company’s Wi-Fi. These devices often have weak security and go undetected by the IT team. That’s where the risk comes in. Hackers can target these devices to sneak into company networks, steal data, or cause system damage. 🔐 Key Takeaways: IoT devices are growing quickly and aren’t always secure. IT teams need better tools to detect unknown devices on their networks. Policies, network segmentation, and user education are essential to reduce this risk. 📌 My Reflection: I found this article really usefu...

🔐 Week 5: Zero Trust Security — Why "Trust No One" Is the New Rule in Cybersecurity

Image
  Hey everyone! 👋 Welcome back to the Cyber Secure Weekly Blog ! This week, we’re talking about something really important in the world of cybersecurity: Zero Trust Security . 🌐 What Is Zero Trust Security? Zero Trust is a new way of protecting networks. The old way was to trust people or devices inside your network and only check outsiders. But today, hackers are getting smarter, and attacks can come from anywhere  even inside your company. So, Zero Trust says: "Never trust, always verify." This means you should check everyone and everything before giving access to your systems or data no matter where they are. 🔑 Key Ideas of Zero Trust Here are some of the main ideas behind Zero Trust: ✅ Verify every time – Don’t trust users or devices just because they’re in the network. 🔐 Give only what’s needed – People should only have access to what they need to do their job. 🚨 Assume breaches happen – Always be ready in case someone gets in. 🧱 Break ...

The Dark Web: What It Is and Why It Matters in Cybersecurity

Image
What It Is: The Dark Web is a hidden part of the internet that you can’t find using normal search engines like Google. To access it, you need special software like the Tor browser. This browser hides your identity and location, so people can go online without being tracked. That’s why the Dark Web is known for anonymous communication. Some people use it for privacy, but others use it for bad reasons. Why It Matters in Cybersecurity: The Dark Web is important in cybersecurity because it’s often used by cybercriminals. They sell stolen data like usernames, passwords, and credit card numbers. You can also find hacking tools and malware there. Cybersecurity experts monitor the Dark Web to find out about new threats before they happen. This helps protect people, businesses, and organizations. It also helps law enforcement track down and stop criminals who use the Dark Web to plan or carry out attacks. In short: Even though the Dark Web is not always bad, it’s often linked to dangerous ...

6 Common Types of Phishing Attacks

  This week, I focused on learning about phishing attacks , and it opened my eyes to just how sneaky and dangerous they can be. Phishing isn’t just one thing.  There are several different forms that cybercriminals use to trick people. Here are the most common types I discovered, and how to recognize them:  🎣 1. Email Phishing The most common type. Scammers send fake emails that look like they’re from trusted companies, trying to get you to click a malicious link or enter your login info. 🛑 Example: “Your bank account is locked. Click here to fix it.” 🎯 2. Spear Phishing More personalized and targeted. These emails use your name, job, or other details to look more believable. 🛑 Example: “Hi please review this document for your class project.” 🐋 3. Whaling Aimed at “big fish” like company executives or managers. These attacks often involve fake invoices or urgent business requests. 🛑 Example: “Urgent from CEO: Send payment to this vendor immediately.” ...

Week 2: What is a Ransomware Attack?

Image
    This week, I learned about ransomware . Ransomware is a type of virus that locks your computer or files. Then the hacker asks for money (a ransom) to unlock them. This is very dangerous because it can stop people from using their computers. Many hospitals, schools, and companies have been attacked with ransomware. Here is an article I read: 🔗 What Is Ransomware? | IBM What I learned: I learned that ransomware can come from bad emails or fake websites. If you click on a bad link, the virus can start. To stay safe, we should not click strange links and always back up our files.

Cybersecurity Ethics: Why Doing the Right Thing Matters?

Image
Why Doing the Right Thing Matters?  In our digital world, we use computers and the internet every day. Cybersecurity is all about keeping these systems and information safe. But it’s not just about technology it’s also about ethics or  knowing what is right and doing the right thing. What Are Cybersecurity Ethics? Cybersecurity ethics means following rules about honesty, privacy, and respect when working with digital information. It’s about protecting people’s data and making sure no one gets hurt. Why Are Ethics Important in Cybersecurity? Building Trust : People trust cybersecurity experts to keep their private information safe. Being ethical means keeping that trust strong. Stopping Harm : Bad actions like hacking, stealing data, or spreading viruses can hurt people and businesses. Ethics help prevent this. Following Laws: Cybersecurity workers have to follow laws and rules. Ethics help them stay on the right path. Creating a Safe Environment: When everyone c...

What I Hope to Learn About Cybersecurity This Semester

As I begin this Computer Security course ( CYBR 332), I’m really excited because it will teach me how to keep information safe from hackers and other threats. In this class, I’ll learn about lots of important things like: Different types of security problems and how to stop them How to control who can access important information How encryption ( secret codes) helps protect data Why privacy matters and the rules we should follow How to keep computer files and networks safe from attacks What I like most is that this course has hands- on labs, so I can practice the skills instead of just reading about them. I hope by the end of the semester, I will know how to protect computers and networks better and be ready for a job in cybersecurity. I’m excited to share what I learn and some cool articles about security with everyone here!