Cybersecurity threat actors are very much like the rest of us in some ways. If something is too difficult, or doesn’t promise enough of a reward, they’ll move on to another initiative.

That’s why the National Cybersecurity Alliance (NCA) is emphasizing “Don’t make it easy for them” as its theme for Cybersecurity Awareness Month 2026. Deterring threat actors starts with easy steps, as the NCA points out:

  • Use long, unique, complex passwords.
  • Turn on multi-factor authentication.
  • Keep your software and operating system up to date.
  • Be wary of phishing emails; when in the slightest doubt, don’t click.

Most of you reading this are in the cybersecurity field or have tech expertise, so you probably just read that and said “Well, duh.” The problem is, malicious actors can be
well-funded – even sponsored by nation-states – and able to use AI to stay ahead of traditional defenses.

Trinity Cyber keeps an eye on the threat landscape, staying on top of evolving TTPs (tactics, techniques, and procedures). For instance:

Unpatched vulnerabilities: Russia’s state-sponsored Cozy Bear threat group (also known as APT29, Midnight Blizzard, or ICE RELIC) often uses unpatched vulnerabilities in Microsoft, VMWare, Fortinet, and other standard business software to gain access to data, including credentials it can use to push its intelligence-gathering and data-theft agenda. You may be thinking “My company isn’t big enough to attract nation-state threat groups’ attention.” In fact, APT29 and others often target smaller organizations, which are more likely to have unpatched software, then use credentials from the small businesses to move on to their larger suppliers, vendors, and partners.

We know that patching applications often falls to a lower priority on the IT department’s
to-do list. Because Trinity Cyber® Full Content InspectionTM (FCITM)
targets the tactics used to exploit the vulnerabilities, customers can rest easy – FCI stops attacks before they get to the target network.

Phishing lures: Forget fake invoices. Sophisticated threat actors can lure high-value targets with phishing attacks that can fool even hardened and experienced people. For instance, APT29 actors may start a Microsoft Teams chat by pretending to be Microsoft support staff investigating a problem, then go on to steal credentials from victims and use them to steal more data. Others may build trust over WhatsApp or Signal – sometimes impersonating trusted contacts using AI-written lures – before moving to steal credentials and establish authenticated access to places they don’t belong.

FCI stops thousands of phishing attacks every day, by targeting the content of messages and by stopping the download of credential-stealing malware. In conjunction with an awareness program and your normal email filters, FCI makes it a lot harder for phishing threats to reach your users.

RDP risks: Remote Desktop Protocol (RDP) can be a big help to IT teams, allowing them to troubleshoot machines many miles away from the technician. If it isn’t carefully managed, though, RDP applications can offer threat actors a path into your systems to steal data and execute malicious code.

APT29 has conducted mass phishing campaigns to send RDP configuration files to national governments and major industries. When launched, these RDP attachments enable remote access to attacker RDP infrastructure, and give full remote control over to adversaries.

Trinity Cyber blocks the malicious configuration files before they hit your perimeter, allowing legitimate RDP traffic without slowing down your users’ experience.

While malicious actors can be wily, clever, and persistent, you don’t have to open the door for them. As you refine your cybersecurity strategies, keep your eye on the basics. While you’re at it, take a look at Trinity Cyber, a powerful cybersecurity platform that prevents threats without setting off a storm of alerts or interfering with the work your team is doing.