Extended Validation Certificates are DeadTroy Hunt·Sep 17, 22:02 UTC · Sep 17, 2018Phishing & fraud30
PayPal's Beautiful Demonstration of Extended Validation FUDTroy Hunt·May 22, 20:28 UTC · May 22, 2019Phishing & fraud30
When Bank Communication is Indistinguishable from Phishing AttacksTroy Hunt·Nov 19, 06:28 UTC · Nov 19, 2019Phishing & fraud30
All websites have something of value for attackers: reputationTroy Hunt·Dec 22, 12:29 UTC · Dec 22, 2016Phishing & fraud30
It’s time that you – the vulnerable human – brush up on your social engineering skills with PluralsightTroy Hunt·Feb 9, 00:00 UTC · Feb 9, 2016Phishing & fraud30
Social Media Thread-Hijacking is Nothing More Than Targeted SpamTroy Hunt·Apr 18, 06:48 UTC · Apr 18, 2018Phishing & fraud30
The Decreasing Usefulness of Positive Visual Security Indicators (and the Importance of Negative Ones)Troy Hunt·May 7, 08:35 UTC · May 7, 2018Phishing & fraud30
Padlocks, Phishing and Privacy; The Value Proposition of a VPNTroy Hunt·Sep 17, 08:44 UTC · Sep 17, 2020Phishing & fraud30
A Sneaky Phish Just Grabbed my Mailchimp Mailing ListTroy Hunt·Mar 25, 07:34 UTC · Mar 25, 2025Phishing & fraud30
On The (Perceived) Value of EV Certs, Commercial CAs, Phishing and Let's EncryptTroy Hunt·Jul 19, 20:29 UTC · Jul 19, 2017Phishing & fraud30
Humans are Bad at URLs and Fonts Don’t MatterTroy Hunt·Oct 28, 07:54 UTC · Oct 28, 2020Phishing & fraud30
Phishing simulations: What works and what doesn'tHelp Net Security·Jul 23, 00:00 UTC · Jul 23, 2025Phishing & fraud30
How cybercriminals exploit psychological triggers in social engineering attacksHelp Net Security·May 6, 00:00 UTC · May 6, 2025Phishing & fraud30
How Everything We're Told About Website Identity Assurance is WrongTroy Hunt·Feb 16, 19:06 UTC · Feb 16, 2022Phishing & fraud30
Beyond Passwords: 2FA, U2F and Google Advanced ProtectionTroy Hunt·Nov 15, 07:42 UTC · Nov 15, 2018Phishing & fraud30