Vivek Raj

Security Content Lead at SecureW2
496 articles published
26 topics covered
About
Vivek Raj has over 8 years of experience in cybersecurity, enterprise SaaS, and technical product marketing, with deep expertise in PKI, RADIUS, 802.1X, and Zero Trust security frameworks. At SecureW2, he works closely with Content, Product, and Marketing teams to translate complex security challenges into practical guidance for customers and IT leaders. Vivek specializes in making advanced identity and network security concepts clear, actionable, and business-focused. He also holds the IBM AI Product Manager Professional Certificate. Besides writing, you can find him watching (or even playing) soccer, tennis, or his favourite cricket.
"The biggest risk in enterprise networking isn't a zero-day exploit — it's a trusted credential that should have been revoked three months ago. Most breaches don't break in. They log in."
Cited by
Articles by

Vivek

A technical guide explaining how FIPS mode restricts cryptographic operations to government-validated algorithms and when organizations must enable it.
Protocols & Standards August 4, 2026
FIPS Mode: What It Is, Why It Matters, and How to Enable It

Most IT administrators encounter Federal Information Processing Standard (FIPS) compliance as a line item in a government contract or an audit finding. Knowing what FIPS mode actually does, and what...

A technical guide to how packet sniffing captures network traffic, the attacks built on top of it, and how certificate-based authentication closes the gap sniffers rely on
Risks & Threats August 2, 2026
What Is Packet Sniffing? How It Works, Risks, and Defense

Anyone with the right software and access to a network segment can capture the traffic moving across it. On an unencrypted or misconfigured network, that traffic can include login credentials,...

Kerberoasting lets an attacker with basic domain user access request crackable Kerberos tickets for service accounts, then break the encryption offline to recover plaintext passwords.
Risks & Threats July 31, 2026
What Is Kerberoasting? Attack Steps, Detection & Defense

Active Directory service accounts run the applications, databases, and scheduled tasks that keep a network running. Many of those accounts were created years ago, never rotate their passwords, and hold...

A single unauthorized Wi-Fi device can hand attackers a direct line into your network, bypassing every firewall rule you’ve written.
Risks & Threats July 23, 2026
Rogue Access Point Attacks: How They Work and How to Stop Them

Every access point on your network is a potential front door. Most of them are points that IT installed and secured on purpose. A rogue access point is one nobody...

A breakdown of MFA fatigue attacks and how phishing-resistant logins prevent them.
Risks & Threats July 11, 2026
What Is MFA Fatigue and How Do Attackers Exploit It?

A stolen password isn’t always enough to get into an account protected by multi-factor authentication (MFA). So, attackers found a workaround: bombard the victim’s phone with authentication requests until they...

The best defense against password spraying is eliminating passwords.
Risks & Threats July 11, 2026
What Is Password Spraying? How It Works and How to Stop It

An attacker does not need to guess your exact password to break into your network. A password spraying attack tests a handful of common passwords against thousands of usernames instead...

A replay attack lets an attacker reuse intercepted login data to impersonate a legitimate user
Risks & Threats July 10, 2026
What Is a Replay Attack? How It Works & Prevention

Passwords and session tokens are meant to prove who you are at a single point in time. A replay attack breaks that assumption. A replay attack is a network security...

This article will explain how the ChromeOS certificate provisioning solution works, and how it provides greater security than the legacy approach.
Integrations June 26, 2026
Google SCEP Deprecation 2026: What ChromeOS Admins Need to Know About Certificate Provisioning

Learn how to migrate from Google's legacy SCEP API to the ChromeOS Certificate Provisioning API before the 2026 deadline.

A plain-language breakdown of how distributed denial of service attacks are built, launched, and what your network can do to reduce exposure.
Risks & Threats June 11, 2026
How Does a DDoS Attack Work? Attack Types & Prevention

Learn how DDoS attacks work, the attack types used, and how to protect networks from disruption.