10/05/2026 | News release | Distributed by Public on 10/05/2026 10:21
October is Cybersecurity Awareness Month, calling attention to the need to protect ourselves against online threats.
Dr. Vitaly Ford, associate professor of Computer Science, is an expert in the computing field, including online security, privacy, and machine learning.
With threats becoming more and more sophisticated each day, he has some tips and tricks for staying safe during Cybersecurity Awareness Month and beyond.
This Q&A has been slightly edited for clarity and length.
What are some of the biggest cybersecurity threats that ordinary people face today? What risks do you think people are still underestimating?
Scammers are still on the rise with fake emails, texts, and phone calls, and it's only getting worse. Free tools like modlishka, evilginx3, and evilworker let them sit between you and a real login page, so they can steal your whole logged-in session and get around normal two-factor authentication (the extra code you type in).
Other common tricks include fake WiFi, downloads that infect your device just from visiting a site, and fake pop-ups on sites that get you to install malware masquerading as an "update." There are even attacks that abuse a weakness in SS7, an old 1970s phone network protocol, or use SIM-swapping-taking over your phone number-to go after high-profile individuals and intercept their text messages and phone calls.
As the list of threats keeps growing, I recommend checking your data leaks through haveibeenpwned.com, haveibeenflocked.com, and att.pentester.com.
With artificial intelligence making it easier to create convincing emails, messages, websites, and even voices, how is AI changing the way people should think about cybersecurity?
With deepfakes, automated attacks, and convincing messages, artificial intelligence has escalated hacking capabilities worldwide. We can even call it vibe hacking at this point.
I recommend "Stop Trusting -> Always Verifying." This should be the motto for any site interaction and message we receive. Is it a bank contacting you? Hang up and call back on a trusted line, go to their site yourself, or check in your bank app. Seeing a pop-up asking you to update your system? Cancel and check for updates separately yourself. Avoid blind downloads without verification of what you get.
If readers want to take immediate actions to become more cybersecurity aware, what would you recommend?
1. Freeze your credit with Equifax, Experian, and TransUnion - it's free. Thawing it is easy and takes only a minute in case you need to apply for a loan or credit card. This will avoid many potential issues with identity theft.
2. Sign up for data breach notifications at haveibeenpwned.com (click on Notify button).
3. Use Cloudflare WARP (https://one.one.one.one). Think of it as a better version of "VPN" because it not only encrypts, but also blocks nasty stuff. If it doesn't work on your device for some reason, try the personal/free version of Proton VPN. Never connect to free WiFi unless you have WARP or a VPN that you trust.
4. Antivirus is far from a panacea, but it will help catch at least the "common cold." Avoid disabling it. But don't install a random antivirus; do your research.
5. Use passkeys or physical keys (e.g., YubiKey), if you can, for your 2FA. The third-best option for 2FA is authenticator apps (e.g., Google Auth).
6. Always, always check what domain you are on.
7. Check the email sender and the original raw email (e.g., in Gmail it's in the top-right corner -> "Show original" menu) and make sure that at the top you see all SPF, DKIM, DMARC as PASS. If not, question the email.
8. Learn about your privacy at operationprivacy.com and deflock.org.