Field notes from the diagnostic layer.
Deep-dives on AI readiness, DNS, security, and the small engineering choices that make domain tooling actually trustworthy.
BigBear 2.0 (Sept 2026): 3,331 Microsoft 365 Victims and the End of MFA-Only Defense
CloudSEK exposed the BigBear 2.0 phishing-as-a-service network — 5,137 stolen credential records, 461 organizations across 40+ countries, and 474 fully MFA-authenticated Microsoft 365 sessions hijacked from a fleet of 42 Vultr proxies. Here is why passwords plus MFA no longer stop credential theft, and how infrastructure-level scanning catches the pattern.
Diwali 2026 Phishing Playbook: 828 Fake Ad Domains, 1-in-3 Indians Duped, and the UPI + Deepfake Trap
McAfee's 2025 Global Holiday Shopping Scams Study — the last full-year India benchmark before Diwali 2026 — found one in three Indians duped by festive-season scams, 37 percent suffering financial loss, average loss over ₹41,500. Quick Heal's Seqrite Labs identified 828 distinct phishing domains running Facebook Ads campaigns in one festive window. Here is the 2026 playbook — the brands attackers impersonate, the domain patterns Domainscan catches, and the 30-second check to run before every festive payment.
Typosquatting in 2026: 301-Redirect Traps, MX Poisoning, and AI-Generated Cover Pages
CrowdStrike Counter Adversary Ops mapped the 2026 typosquat playbook — 301 redirects that hide the phishing site while the MX record silently steals email, Cloudflare Ray-ID geo-filters that show clean pages to security researchers, and AI-generated "domain for sale" cover art. Bitdefender puts the AI-driven phishing surge at 70 percent. Here are the mechanics and the infrastructure checks that catch them.
86% of Enterprises Hit a Certificate Outage This Year (Keyfactor 2024)
Keyfactor's 2024 PKI & Digital Trust Report: 86% of surveyed organisations logged at least one certificate-related outage in the past 12 months, 31% at least quarterly, ~10% weekly. Only 32% run a formal certificate lifecycle tool. Now compress the renewal cadence 8× under the CA/Browser Forum's 47-day ballot by March 2029 and calculate what breaks first.
The 2024 Cost of a Data Breach: $4.88M and Rising
IBM's 2024 Cost of a Data Breach Report pegged the global average at $4.88M — up 10% year-over-year, the largest single-year jump since the pandemic. Phishing-initiated breaches averaged $4.76M and the mean time to identify plus contain a breach was 258 days. US average: $9.36M. Healthcare: $9.77M for the fourteenth consecutive year on top. Sector-by-sector breakdown and what "cut detection time" is worth on the invoice.
The DMARC Enforcement Gap: 78% Publish, Only 42% Enforce
Valimail's 2026 State of DMARC pegs publication at 78% of the top million domains, but real enforcement (p=quarantine or p=reject) sits at just 42%. Fortune 500 adoption is 93.8% — yet only 62.7% enforce. p=none protects nobody. Here is why the gap exists, what Google/Yahoo's Feb 2024 bulk-sender rules changed, and the 30-day path from p=none to p=reject.
The Ericsson-O2 SSL Outage: How One Expired Certificate Cost £100M
December 6, 2018. One expired software certificate in Ericsson's SGSN-MME took roughly 32 million O2 UK subscribers offline, plus tens of millions of SoftBank Japan users and customers across 11 countries. O2 later sought approximately £100M in damages. Here is the timeline hour by hour, the root cause SMB teams still miss under the words "auto-renew", and why the CA/Browser Forum's move to a 47-day certificate lifetime by 2029 makes the O2 incident a rehearsal.
The $121M Lookalike-Domain BEC: What Rimasauskas Taught Every CFO
2013–2015. A Lithuanian named Evaldas Rimasauskas registered a lookalike of hardware vendor Quanta Computer, forged invoices, and wired roughly $121M out of Facebook and Google before either company noticed. Arrested 2017. Guilty plea March 2019. Five years plus $49.7M forfeiture, December 2019. Why DMARC at p=reject and a lookalike-domain monitor would have shut the entire scheme down inside a week.
FBI IC3 2024: $2.79B in BEC Losses (and Why That's Only a Fraction)
The FBI Internet Crime Complaint Center's 2024 Annual Report logged 21,442 business email compromise cases totalling roughly $2.79B in reported US losses — bringing the 2022–2024 cumulative to about $8.5B. Total IC3 losses across all crime types hit a record $16.6B. Full breakdown, why the true BEC figure is a multiple of what got reported, and what preventing one incident is actually worth on your books.
Watching Only the Apex: How Ignoring Subdomains Turns Into a Six-Figure Incident
Your uptime checks are on example.com. Your SSL monitor is on example.com. Your DMARC alerts fire on example.com. Meanwhile api., staging. and blog. are running unmonitored — and that is exactly where attackers live. Here is what apex-only monitoring misses, why it keeps costing companies money, and how to fix it in an afternoon.
MCP for AI agents — what Model Context Protocol unlocks, and how live domain intelligence fits in
A plain explanation of MCP, the problem it solves, and the five patterns it unlocks for AI agents — with worked examples of grounding an agent in live WHOIS, DNS, SSL, blacklist and email-auth data.
Amazon Prime Day 2026: 6,843 Fake Domains and the End of Manual Phishing Detection
Check Point Research flagged 6,843 Amazon-themed domains registered ahead of Prime Day 2026 — one in thirteen explicitly malicious. Industrial-scale phishing now ships with valid SSL. Here is why padlocks no longer save you, and how infrastructure-level scanning does.
How to Check If a Website Is Safe Before You Pay: 7-Step Verification Guide
Before you type a card number or scan a UPI QR, run a website through these seven checks. Each one takes under a minute, and most fake sites fail at least three of them.
Payment Scam Websites: 12 Red Flags Fraudsters Hope You Miss
The exact patterns that show up on fake checkout pages — newly-registered domains, hidden WHOIS, suspicious nameservers, fake trust badges, and the QR-code tricks costing Indians ₹400 crore a year.
Lookalike Domains & Typosquatting: How Scammers Hijack Your Checkout
A walkthrough of the URL tricks behind most payment phishing — typo swaps, dash insertions, homograph attacks, and punycode spoofs — with real examples and the WHOIS checks that catch them.
The HTTPS Padlock Lie: Why SSL Doesn’t Mean a Website Is Safe to Pay On
The padlock icon only proves the connection is encrypted. It doesn’t verify who runs the site. Most phishing pages in 2026 have valid SSL — here’s what to actually check.
Fake Courier & Delivery Scam Sites: The 2026 Playbook (India Post, DHL, FedEx Lookalikes)
Inside the ₹25 redelivery scam: how fraudsters impersonate India Post, DHL, FedEx, and Blue Dart, the SMS hooks they use, the tracking pages they clone, and how to verify a courier URL in under a minute.
AI Readiness: the new SEO surface area in 2026
Why every domain needs to think about how GPTBot, Claude-Web, and PerplexityBot see it — and the five signals that actually move the needle.
llms.txt explained — a markdown TOC for LLMs
The emerging convention for telling AI systems which of your pages matter most. With examples from GitHub, Anthropic, and Cloudflare.
One short email when we publish.
~2 posts a month, no marketing, unsubscribe in one click.