Network Security Basics

Explore top LinkedIn content from expert professionals.

  • View profile for Alan Robertson

    AI Governance Consultant | Responsible AI for Regulated Industries | Writer & Speaker | Discarded.AI

    20,482 followers

    This is wild McDonalds: Admin password: 123456. That’s all it took to access the back-end of McDonald’s AI hiring chatbot and with it, the data of up to 65 million job applicants. This wasn’t a hypothetical. Two security researchers managed to log into the Paradox system that powered McHire, McDonald’s recruitment tool, and access names, email addresses, phone numbers, and transcripts of conversations with its AI bot “Olivia.” No MFA. No rate limits. No detection. Just a widely known default password and full admin access to the entire recruitment platform. The platform was swiftly taken offline once notified. But the damage is done not by hackers, but by sheer negligence. McDonald’s has pinned the issue on Paradox. Paradox says they fixed it and have since launched a bug bounty programme. But it raises bigger questions for all of us: ↳ Who audits the third-party vendors we automate hiring with? ↳Where does the liability sit when trust is breached at this scale? ↳And what does ‘responsible AI’ even mean when basic cybersecurity hygiene isn’t in place? We talk about ethics, bias, explainability. But sometimes it’s just about… setting a password. #AIinHiring #CyberSecurity #ResponsibleAI #DataGovernance #ThirdPartyRisk *note all Tshirt images are AI generated and not real or in anyway purchasable.

  • View profile for Caitlin Sarian
    Caitlin Sarian Caitlin Sarian is an Influencer

    3.0M+ Followers | Empowering Global Cybersecurity | Multi-Award-Winning Cybersecurity Leader & Influencer | 40 Under 40 | Keynote Speaker | Advocate for Diversity & Women in Tech | CEO & Cybersecurity Educator

    78,320 followers

    7 things I no longer do with my phone as a Cybersecurity expert: 1. Never use SMS as your two-factor authentication. Text-based codes can be intercepted. Through something called a SIM swap attack, a criminal can trick your carrier into transferring your phone number to their device and get into your accounts. Use an authenticator app instead. 2. Never leave Bluetooth on when you’re not using it. Bluetooth is a wireless signal anyone nearby can probe. Turn it off when you’re out in public. 3. Never reuse the same password across multiple accounts. If one account gets breached, every account with that same password is now compromised. A password manager makes it easy to have unique passwords for everything. 4. Never click links in text messages you weren’t expecting. Smishing is phishing via text and it is one of the fastest growing scams right now. Even if it looks like it’s from your bank, go directly to the app or website instead. 5. Never plug into a public USB charging station. A charging port can also be a data port. Cybersecurity experts have shown that ordinary-looking cables can give a hacker full remote access to your device. Bring your own charger and plug into a wall outlet. 6. Never ignore software updates. Updates patch security vulnerabilities. Every day you delay is a day hackers can exploit what has already been fixed. 7.Never save passwords in your Notes app. (Unless you have it biometrically locked down) Your Notes app is not encrypted. If someone gets into your phone, they get everything. Use a password manager instead. Follow @cybersecuritygirl for more iPhone safety tips

  • View profile for Mayank Kumar
    Mayank Kumar Mayank Kumar is an Influencer
    69,638 followers

    Tech is changing everything-  including how we get scammed. I’ve spent years preaching the power of technology to uplift lives. But here’s the side we don’t talk about enough: Tech is also making fraud faster, smarter, and frighteningly believable. A few weeks ago, someone impersonated me, same name, same display picture, same texting style. They messaged a team member in Germany asking for money. It almost worked. But thankfully, he paused, verified, and picked up the phone. Crisis averted. But this isn’t my first run-in. Even at upGrad, we saw our fair share. We all know big companies are vulnerable to this. But what’s alarming is how younger startups are too. The modus operandi is simple but smart: Scan for recent press or LinkedIn buzz, then impersonate a leader and reach out with just enough familiarity to bypass doubt. Voice clones, AI-written bios, deepfakes, spoofed numbers. Scammers don’t need your passwords now. They just need your LinkedIn profile and five minutes of your voice. So how do we deal with it? Here’s what I’ve learned: 1. Always verify on another channel (Call > Text) If something feels off, pick up the phone. Scammers rely on staying in the same thread. 2. Urgency is a red flag, not a call to action “Act now” is fraud’s favorite tactic. Pressure is their playbook. 3. Normalize double-checking. Even with leadership. Especially with leadership. Team members might hesitate to question a senior's message. Empower them to pause and check. It’s not awkward. It’s smart. Trust grows through clarity. Have you faced something similar? How are you staying one step ahead? Let’s learn from each other.

  • View profile for Bob Carver

    CEO Cybersecurity Boardroom ™ | CISSP, CISM, M.S. Top Cybersecurity Voice

    53,431 followers

    Hundreds of Brother printer models have an unpatchable security flaw -The Verge PSA: Remember to change the manufacturer’s default passwords on ALL your devices. Serious security flaws have been found in hundreds of Brother printer models that could allow attackers to remotely access devices that are still using default passwords. Eight new vulnerabilities, one of which cannot be fixed by patching the firmware, were discovered in 689 kinds of Brother home and enterprise printers by security company Rapid7. The flaws also impact 59 printer models from Fujifilm, Toshiba, Ricoh, and Konica Minolta, but not every vulnerability is found on every printer model. If you own a Brother printer, you can check to see if your model is affected here. The most serious security flaw, tracked under CVE-2024-51978 in the National Vulnerability Database, has a 9.8 “Critical” CVSS rating and allows attackers to generate the device’s default admin password if they know the serial number of the printer they’re targeting. This allows attackers to exploit the other seven vulnerabilities discovered by Rapid7, which include retrieving sensitive information, crashing the device, opening TCP connections, performing arbitrary HTTP requests, and exposing passwords for connected network services. While seven of these security flaws can be fixed via firmware updates detailed in Rapid7’s report, Brother indicated to the company that CVE-2024-51978 itself “cannot be fully remediated in firmware,” and will be fixed via a change to the manufacturing process for future versions of affected printer models. For current models, Brother recommends that users change the default admin password for their printer via the device’s Web-Based Management menu Changing default manufacturing passwords is something we should all be doing when we take a new device home anyway, and these printer vulnerabilities are a good example as to why. #cybersecurity #printers #IoT #vulnerabilities #defaultpassword #updatenow

  • View profile for Shiv Kataria

    Securing Critical Infrastructure & Global Manufacturing | OT/ICS Security Strategy & Governance | IEC 62443 · CISSP · GIAC GRID | AI for Cyber Defense

    25,448 followers

    𝗜𝗖𝗦 𝗔𝗰𝗰𝗲𝘀𝘀 𝗖𝗼𝗻𝘁𝗿𝗼𝗹: 𝗞𝗲𝗲𝗽𝗶𝗻𝗴 𝗖𝘆𝗯𝗲𝗿 𝗧𝗵𝗿𝗲𝗮𝘁𝘀 𝗢𝘂𝘁 𝟯:𝟬𝟬 𝗮.𝗺. 𝗶𝗻 𝗮𝗻 𝗲𝗻𝗲𝗿𝗴𝘆 𝗽𝗹𝗮𝗻𝘁: An operator sees the cursor moving—on its own. In 2021, hackers actually took control of a Florida water plant, nearly poisoning the water. Why? Shared passwords and open remote access. Access control in Industrial Control Systems (ICS) isn’t just IT hygiene—it’s a frontline defense. Unlike IT, ICS must balance security vs. uptime, making access control complex. 𝗞𝗲𝘆 𝗖𝗵𝗮𝗹𝗹𝗲𝗻𝗴𝗲𝘀 𝗶𝗻 𝗜𝗖𝗦 𝗔𝗰𝗰𝗲𝘀𝘀 𝗖𝗼𝗻𝘁𝗿𝗼𝗹 ❌ Default & Shared Credentials – Many OT devices still use factory-set or hardcoded passwords. ❌ Overprivileged Accounts – Admins using the same account for both daily tasks & critical operations. ❌ Uncontrolled Remote Access – Unrestricted RDP, TeamViewer, or VPN access directly into OT. ❌ Lack of Continuous Audits – Old user accounts lingering long after employees leave. 𝗣𝗿𝗮𝗰𝘁𝗶𝗰𝗮𝗹 𝗦𝗼𝗹𝘂𝘁𝗶𝗼𝗻𝘀 (Aligned with IEC 62443) ✏️ Kill Default Credentials – Change all default passwords before deployment. Use compensating controls if you can’t. ✏️ Unique, Least-Privilege Accounts – No shared logins. Admins should have separate work and privileged accounts. ✏️ Secure Remote Access – Jump servers, MFA, and firewalls between IT & OT. No direct access to controllers. ✏️ Regular Audits & Offboarding – Disable accounts immediately when employees or contractors leave. 𝙍𝙚𝙘𝙚𝙣𝙩 𝙇𝙚𝙨𝙨𝙤𝙣: The Florida water plant breach could have been prevented with MFA, segmented access, and unique passwords. Simple steps can block attackers from turning small mistakes into disasters. ICS security is about access—who gets in, what they can do, and when they’re removed. Every login should tell a secure story. #ICS #CyberSecurity #IEC62443 #AccessControl #OTSecurity

  • View profile for Kevin Walker

    Helping schools and smaller organisations know what to fix first | Practical cyber security. Plain English. No scare tactics. | Founder, Black Swan Cyber Security Solutions

    2,213 followers

    McDonald's "I'm lovin' it" approach to cyber security needs some serious work. When your AI hiring bot can be breached with the password "123456," you're definitely NOT "lovin' it" anymore. 64 million job applicants had their personal data exposed through McHire's laughably weak security. As cyber security professionals, this breach serves up several important lessons: ❌ Default credentials are a McFlurry of disaster waiting to happen - the researchers gained admin access using "123456:123456" credentials that hadn't been changed since ❌ Third-party vendor security can't be an afterthought - McDonald's trusted Paradox.ai with sensitive applicant data, but clearly didn't have adequate security oversight. ❌ AI systems need the same security rigour as any other critical infrastructure - just because it's "smart" technology doesn't mean it's secure by default On a positive note, both companies responded quickly, patching the vulnerability the same-day and Paradox.ai launched a bug bounty program. Sometimes you need ethical hackers to show you that your security is anything but "golden." For the millions affected: Change your passwords, enable 2FA, and watch for phishing attempts. This breach shows why job seekers' personal data deserves the same protection as any other sensitive information. When it comes to cyber security, there's no "happy meal" - just the hard work of implementing proper security controls. #CyberSecurity #DataBreach #AISecuriy #McDonald's #InfoSec #ImLovinIt https://lnkd.in/d7iAs8iQ

  • View profile for Alvin Rodrigues
    Alvin Rodrigues Alvin Rodrigues is an Influencer

    I help organisations turn their people into their strongest security asset | Cybersecurity Awareness Trainer | Keynote Speaker | Author | Human Firewall Builder and Behaviour Change Specialist

    10,692 followers

    123456: Key to 64 Million Job Seekers 123456: the password that opened the doors to 64 million job seekers’ data All because no one asked who was responsible for a simple security check Problem On 30 June 2025, two security researchers logged into McDonald’s AI hiring system, McHire, using the factory default credentials “123456” for both username and password. Inside, they found an insecure API that let them iterate applicant IDs and pull names, emails, phone numbers, postal addresses, personality-test answers and chat transcripts for some 64 million candidates. Agitate This was not a nation-state hack or zero-day exploit. It was a test account, created before 2019 by Paradox.ai, that remained active in production without multi-factor authentication or a single audit. Paradox failed to disable or secure its legacy admin interface. McDonald’s, in turn, failed to verify vendor security hygiene or enforce routine penetration tests. Ultimately, McDonald’s held the keys to its applicants’ data and never bothered to check if they were still on the door. The impact is clear: if cybercriminals had found those credentials first, they could have mounted large-scale phishing, identity theft, or blackmail campaigns. Millions of people would have been at risk because no one took ownership of a trivial but critical security step. Solution True security starts with clarity on accountability. Paradox.ai should never have left a test account alive in a live environment. McDonald’s should never have accepted a vendor deliverable without formal security validation. Both parties share responsibility, but the data controller, McDonald’s, bears ultimate accountability for protecting applicant data. Word of caution If it was a real hack and if you had applied for a job at McHire, you should change your McDonald's password immediately. Additionally, if you used that username or password on any other site, please change those as well. The main message here is to use a unique password for all your important accounts. Call to Action Awareness does not equal behaviour. Every minor inconvenience adds to the pile of risk your company faces. What steps has your organisation taken to continuously check for small security gaps that could one day be exploited? #alvinsratwork#ExecutiveDirector#cybersecurity#cyberhygiene#Cyberawareness#BusinessTechnologist#Cyberculture 

  • View profile for Talila Millman

    Global CTO | Board Director | Advisor Strategic Innovation | Change Management | Speaker & Author

    10,746 followers

    Your home and office devices can be used in cyberattacks. Here’s what to do. The US government disrupted a Chinese hacking operation that utilized compromised small office and home office network equipment, including routers, firewalls, and VPN hardware to route their traffic.  But employing simple cyber hygiene we will discuss below can keep your home, your business and/or your company safe. How Hackers Invaded: Hackers exploited vulnerabilities in outdated devices, especially those nearing "end-of-life" status and no longer receiving security updates. They then used known weaknesses to gain control and reroute their malicious traffic through these devices, making it harder to detect their real targets. Why They Do It: These compromised devices act as "stepping stones," hiding the hackers' tracks and making it harder to pinpoint their true intentions. It's similar to the 2016 attack on internet provider Dyn, when hackers launched a massive internet outage affecting websites such as Amazon, PayPal, Walgreens, Visa, CNN, Fox News, Wall Street Journal, and the New York Times. At that time, hackers took control of routers, cameras, Printers, and other devices by using the default password coming out of the factory. 🛡 Simple Steps to Secure Your Home and Office: ➡️ Update, Update, Update: Regularly update your router, firewall, VPN, and all connected devices with the latest security patches. Most devices offer automatic updates - enable them! ➡️ Ditch the old tech:  If your router or other devices are nearing end-of-life, invest in newer, secure models. ➡️ Password Power: Set strong, unique passwords for all your devices and enable two-factor authentication wherever possible. Hackers love easy prey, make them work for it! ➡️ Firewall Fortitude: Enable your firewall and anti-virus and configure both to detect and block suspicious activity. Think of it as a security guard for your digital life. For Companies: While the above advice works for both individuals and companies, companies should assume they will be hacked and be prepared.  The preparation must include at least: ♦︎ Off-network backup, ♦︎ Incident response action plan ♦︎ Disaster recovery plan What are you doing to keep your home equipment and your company secure? #cyberdefence #cybersecurity #levelUpYourLi _______________ ➡️ I am Talila Millman, a fractional CTO,  a management advisor, a keynote speaker, and an executive coach. I help CEOs and their C-suite grow profit and scale through optimal Product portfolio and an operating system for Product Management and Engineering excellence.  📘 My book The TRIUMPH Framework: 7 Steps to Leading Organizational Transformation will be published in Spring 2024. You can preorder a signed copy on my website Image credit: Bing AI powered by DALL-E3

  • View profile for Amit Jaju
    Amit Jaju Amit Jaju is an Influencer

    Global Partner | LinkedIn Top Voice - Technology & Innovation | Forensic Technology & Investigations Expert | Gen AI | Cyber Security | Global Elite Thought Leader - Who’s who legal | Views are personal

    14,928 followers

    India faced an average of 2807 attacks per week in Q1 2024, a 33% YoY increase, becoming one of the most targeted nations in the world, according to Checkpoint Research Report. Also, a notable increase in the average number of cyber attacks per organization per week, reached 1308, marking a 5% increase from Q1 2023. The Education/Research sector suffered the most, with an average of 2,454 attacks per organization weekly, making it the top target among industries. Following closely are the Government/Military sector with 1,692 attacks per week and the Healthcare sector with 1,605 attacks per organization per week, highlighting significant vulnerabilities in critical sectors essential to societal function. These numbers highlight a worrying trend of rapid escalation in cyber threats. So, what steps can organizations globally take to bolster their cybersecurity defenses? Here are a few recommendations: Awareness and Training: Educate employees about cybersecurity best practices, including identifying phishing attempts and avoiding suspicious links or downloads. Regular Vulnerability Assessments: Conduct regular security assessments to identify weaknesses in the IT infrastructure and applications, and promptly address any vulnerabilities. Multi-Factor Authentication (MFA): Implement MFA across all accounts and systems to add an extra layer of security and protect against unauthorized access. Incident Response Plan: Develop a comprehensive incident response plan that outlines steps to be taken in case of a cyberattack. Regularly test and update the plan to stay prepared. Advanced Threat Protection: Invest in advanced threat protection solutions that can detect and mitigate sophisticated cyber threats, including those that utilize AI-based tools. Data Encryption: Encrypt sensitive data both at rest and in transit to ensure that even if it gets intercepted, it remains unintelligible to unauthorized users. Continuous Monitoring: Deploy robust monitoring systems to detect and respond to cyber threats in real-time, reducing the dwell time of attackers within the network. #Cybersecurity is a continuous process. As cybercriminals constantly evolve their tactics, so should our defenses. #Cyberattacks #ThreatIntelligence #Cybersecurity

  • View profile for Vivek P.

    Director & Head - Cyber Intelligence | CISM | IAM | PAM | SSO | SAML | OAUTH | MFA | EPM | EDR | SIEM | DLP | GRC | Oracle | Sailpoint | Delinea | BeyondTrust | Cyberark | Ping | Forgerock

    12,616 followers

    “Bro, I sent you a six-digit code by mistake. Can you share it with me?” If you get a message like this, do NOT reply. Do NOT send the code. Do NOT even think twice. Because guess what? That’s not your bro. That’s a scammer who has already hijacked your bro's account. Here’s how this scam works: 1. They next trigger a login request on your WhatsApp stealing information from the hijacked account's contacts. 2. You receive a real OTP from WhatsApp. 3. Since they are your trusted contact messaging you and asking you to share it, you don't suspect them. 4. You send it. 5. Boom, your account is gone. Now, the scammer impersonates you. They message your contacts saying they’re in trouble and need urgent money. Your friends and family, thinking it’s you, send the money. And just like that, you become the reason someone got scammed. Rule #1 of WhatsApp: NEVER share an OTP with ANYONE. Not even if it’s your best friend, your boss, or your grandma asking. Call them first. But can we trust verified identities? Here’s the real cybersecurity mind-bender: Just because someone owns an account doesn’t mean they are the one operating it. Account Owner ≠ Account Operator. The moment someone else controls the account, it’s no longer “them.” Even if the profile picture, name, and chat history match, the person behind the screen could be a scammer. This is why businesses lose money to fake invoices, HR sends salaries to fraudsters, and even CEOs fall for phishing attacks. Because they trust the “identity” and forget to verify the operator. What can WhatsApp do to protect an account owner? Introduction of digital identity and zero trust can be a solution. ✔️ No biometrics match? No new access to the account. ✔️ No passkeys, no login. How to protect yourself: ✔️ Never share OTPs. Not with anyone. Not for any reason. ✔️ Enable two-step verification. It’s like putting a deadbolt on your digital door. ✔️ Don’t trust messages asking for money. Always call and confirm. ✔️ Be suspicious of urgent requests. Scammers use urgency to bypass logic. ✔️ Don’t click on random links. Even if it looks legit. Cybersecurity isn’t just about firewalls and antivirus software. It’s about knowing how scammers think, and staying one step ahead. Stay safe. Stay skeptical. Stay unscammable. Have you or someone you know ever fallen for a scam like this? Drop your stories in the comments. Let’s make sure no one else gets tricked. 📌 P.S. As a trusted cybersecurity specialist, I can help you assess your cybersecurity risks and recommend the right solutions for your business. Please feel free to contact me if you have any questions or need assistance. #cybersecurity

Explore categories