CaptiveCrunch: When the Network Is the Phish
CaptiveCrunch turns the captive portal itself into the phish, and MFA does not answer it. How the chain works, and what your simulations never covered.
Read the post →Phishing, vishing, and pretexting as tested controls rather than annual compliance exercises, and what click-rate data does and does not tell you.
9 posts
CaptiveCrunch turns the captive portal itself into the phish, and MFA does not answer it. How the chain works, and what your simulations never covered.
Read the post →One phishing simulation a year measures a single day with a single pretext. Why cadence beats the annual checkbox, and which metric is worth reporting.
Read the post →Bad grammar and generic greetings no longer identify a phishing email. The tells that still work: the ask itself, the channel, and unexplained urgency.
Read the post →A video call from your boss authorising an urgent payment, except it is not her. A plain guide to deepfakes and the process changes that defeat them.
Read the post →One in three phishing attempts now happens outside email, and LinkedIn is where your staff are easiest to reach. What that changes about your defences.
Read the post →Phishing works on people, not systems, which is why filters alone never finish the job. Training, technical controls, and testing that reflects real attacks.
Read the post →Credential stuffing is unsophisticated and works anyway, because people reuse passwords. How the attack runs, and which controls actually blunt it.
Read the post →Attackers register domains that look almost exactly like yours. How typosquatting and cheap top-level domains work, and how to get ahead of both.
Read the post →Phishing is still the number one way organizations get breached. Why technical controls alone do not stop it, and what a realistic test program looks like.
Read the post →Tell us what you need tested. We’ll come back with scope, timeline, and a fixed price.