I spend a lot of time reading about cyberattacks. Lately, some of those stories have changed what I do when I close the laptop and become an ordinary internet user again.
Cybersecurity Awareness Month is underway this October with the theme “Don’t Make It Easy for Them.” The National Cybersecurity Alliance is emphasizing four basic behaviors: using strong passwords and a password manager, enabling multifactor authentication, recognizing and reporting scams, and keeping software updated.
Those recommendations sound simple. But after covering exploited browser vulnerabilities, MFA-bypassing phishing attacks, massive data exposures, and campaigns that weaponize software people already trust, I’ve found some of those habits much harder to dismiss.
Here are four things I’m doing differently in 2026.
1. I install security updates much faster
I used to treat software updates as interruptions. If an update appeared while I was working, clicking “later” was easy. I’m much less comfortable doing that now.
In September alone:
- Google patched multiple Chrome vulnerabilities that attackers were already exploiting. On Sept. 3, Google disclosed an exploit for CVE-2026-85046, a high-severity type confusion vulnerability in Chrome’s V8 engine.
- Five days later, Google disclosed another actively exploited vulnerability, CVE-2026-87491.
- And Chrome 154, released later in the month, contained fixes for 108 security vulnerabilities, including multiple critical flaws.
My takeaway is simple: I no longer assume I have days or weeks to install a security update. When an update fixes an actively exploited vulnerability, the clock has already started.
2. I don’t assume MFA means my account is safe
I still use multifactor authentication, and I absolutely wouldn’t turn it off. But 2026 has given me a much better appreciation for what MFA can and cannot do.
In September, researchers uncovered a phishing-as-a-service operation called BigBear 2.0 that was designed to steal authenticated Microsoft 365 sessions. As eSecurity Planet reported in its coverage of the BigBear 2.0 campaign, CloudSEK said the campaign targeted 461 organizations and successfully bypassed MFA at 258 of them.
Instead of simply stealing a username and password, such attacks can capture session cookies after a victim has authenticated.
That changes how I think about suspicious login pages. I used to think of MFA as the safety net that could rescue me if I accidentally entered a password somewhere I shouldn’t. Now I treat the login page itself as part of the security decision.
Before entering credentials, I pay more attention to how I got to the page, its domain, and whether I expected to sign in at all.
MFA remains one of the most important protections I use. I just don’t treat it as invincibility armor.
3. I’m more suspicious of things that look legitimate
The old stereotype of phishing is almost comforting: terrible grammar, a suspicious attachment, and an email from a prince who urgently needs your bank account.
Real attacks are getting much harder to spot.
Researchers this year have documented phishing campaigns that abuse legitimate services, authentication workflows, and other trusted infrastructure. For example, Barracuda research, covered by eSecurity Planet, found that attackers are increasingly targeting session tokens and abusing legitimate services to make attacks harder to distinguish from normal activity.
Another campaign spread across 46 countries using fake invoices, tax documents, and other business lures to convince victims to install legitimate remote monitoring and management software. eSecurity Planet’s coverage of the RMM phishing campaign showed how attackers can turn software typically used by IT administrators into a means of gaining remote access.
That has changed one of my own mental shortcuts. I no longer ask only, “Does this look legitimate?” I ask, “Was I expecting this?”
An authentic-looking Microsoft login, document request, invoice, or software installer isn’t automatically trustworthy just because the branding looks right or the software itself is legitimate.
4. I assume some of my personal information is already exposed
Data breaches have also changed the way I think about privacy. The lesson isn’t that protecting personal information is pointless. It’s that I don’t want the security of my accounts to depend on information about me remaining secret forever.
Recent incidents illustrate the problem.
In September, a Texas breach filing reported that the IDScan.net incident affected 13 million people. That came weeks after a dark-web marketplace claimed to possess more than 153 million U.S. and Canadian driver’s license records allegedly connected to the company. As eSecurity Planet reported in its coverage of the IDScan breach, the two figures describe different things and shouldn’t be treated as interchangeable.
The 13 million figure represents the number of people reported to have been affected by the breach. The much larger 153 million figure originated from cybercriminals’ claims about records allegedly offered through the Nexus dark-web marketplace. IDScan has not publicly confirmed that 153 million driver’s license records were stolen.
That distinction matters because attacker claims should never automatically be treated as confirmed facts. But even a breach affecting an estimated 13 million people demonstrates how much sensitive personal information can be put at risk without the individuals involved having any control over it.
So I try not to rely on information such as my birthday, address, phone number, or other personal details as proof that someone contacting me really knows me.
An attacker knowing something about me doesn’t mean I should trust them. In some cases, it may be the exact reason I shouldn’t.
Cybersecurity awareness means changing the small habits
Cybersecurity Awareness Month can easily become a collection of advice everyone has heard before: use better passwords, enable MFA, don’t click suspicious links, and install your updates.
All of that advice is still useful. What has changed for me is the urgency behind it.
The attacks I’ve covered this year show how quickly vulnerabilities can move into active exploitation, how phishing can bypass protections we trust, and how legitimate services can be incorporated into attacks.
I haven’t stopped using the internet, and I don’t inspect every email as if it had arrived wrapped in crime-scene tape. I’ve just added a little more friction before I trust something.
I update sooner. I check where login pages came from. I use MFA without assuming it can save me from every mistake. And I treat unexpected requests for information with more suspicion, even when they look legitimate.
That’s probably the Cybersecurity Awareness Month lesson I’ll keep after October ends: attackers keep looking for the easiest opening, and sometimes making their job harder starts with changing one small habit.
Also read: N0va Phishkit Targets North America and Europe Through Microsoft Logins to see how attackers are abusing legitimate Microsoft authentication flows to steal access even after victims complete MFA.





