Author name: POPP3R

Security Awareness for Nonprofits: The Interlock Problem

The clients of the Centre for Newcomers came to Calgary for a fresh start. On July 17, 2026, they got something else: their personal records, immigration files, and sensitive status documents became part of a 380 GB haul claimed by the Interlock ransomware group. The organisation, a Calgary-based nonprofit providing immigration and settlement services across […]

Security Awareness for Nonprofits: The Interlock Problem Read More »

Ransomware Awareness Training: The July Imperative

A single compromised employee account was all it took for ShinyHunters to access 70,000 Canadians’ personal records at Canada Life in April 2026. No exotic vulnerability, no extended campaign: one credential, one door left unlocked, and a major Canadian financial services provider was facing a data breach notification and an extortion deadline simultaneously. For the

Ransomware Awareness Training: The July Imperative Read More »

The SharePoint Zero-Day and Employee Security Training

Every second Tuesday of the month, Microsoft releases security updates, and IT teams across the country quietly begin a race against exploitation. This month, the stakes are higher than usual. Microsoft’s April 2026 Patch Tuesday addressed 167 vulnerabilities, including eight rated critical and two zero-days, one of which is already being actively exploited in the

The SharePoint Zero-Day and Employee Security Training Read More »

Booking.com Breach Is a Social Engineering Defence Lesson

Booking.com confirmed on April 13, 2026 that unauthorized parties accessed customer reservation data through a third-party compromise. The stolen information included names, email addresses, phone numbers, postal addresses, and messages guests had exchanged with hotels through the platform. Financial data was not exposed, but the immediate weaponization of that booking data in follow-up attacks tells

Booking.com Breach Is a Social Engineering Defence Lesson Read More »

$500 Phishing Kits Demand a Cybersecurity Culture Shift

Last week, the FBI and Indonesia’s National Police dismantled the W3LL phishing network, arresting the alleged developer and seizing the platform’s infrastructure. It was a meaningful enforcement milestone: the first coordinated action between American and Indonesian authorities targeting a phishing kit developer. But the headline about the arrest misses the more important story. The W3LL

$500 Phishing Kits Demand a Cybersecurity Culture Shift Read More »

Payroll Pirates Reveal Canada’s Human Risk Gap

On April 9, 2026, Microsoft’s security researchers published their investigation into Storm-2755, a financially motivated threat actor running what they are calling “payroll pirate” attacks against Canadian employees. The campaign does not rely on malware, ransomware, or headline-grabbing intrusions. It relies on two things that are already inside your organization: a staff member who Googled

Payroll Pirates Reveal Canada’s Human Risk Gap Read More »

When Teams Is the Trap: Rethinking Phishing Prevention

The attack unfolded through tools that would look routine to any working professional: a LinkedIn connection from a credible-seeming contact, an invitation to a Slack workspace that appeared genuinely company-branded, and then a Microsoft Teams video call that stalled with a familiar-looking technical error. The suggested fix was a software update. One developer clicked, and

When Teams Is the Trap: Rethinking Phishing Prevention Read More »