Marcus Chen

Articles by Marcus Chen

European financial district skyline representing the EU financial sector reporting ICT incidents under DORA
Compliance & RegulationsThreat Intelligence

DORA Year One: What 3,383 Major ICT Incidents Reveal

The European Supervisory Authorities have published the first annual report on major ICT incidents under DORA: 3,383 reports in 2025, most from the credit and payments sectors. Here is what the numbers show, and why the 4-hour reporting clock depends on people as much as process.

Marcus Chen·8/26/2026·6 min read
Employee seeing an instant training lesson after clicking a simulated phishing email
Phishing & Social EngineeringProduct Updates

Teachable Moments: Just-in-Time Phishing Training on Click

When an employee clicks a simulated phishing link, empowsec turns the mistake into an instant micro-lesson: a Teachable Moment page that explains the exact red flags they just missed, at the moment they are most receptive to learning.

Marcus Chen·8/7/2026·6 min read
Employee receiving an unexpected phone call at an office workstation
Phishing & Social EngineeringThreat Intelligence

Vishing Campaign Abuses Entra Passkey Enrollment Flow

A vishing crew is calling employees as fake Microsoft IT staff and walking them through a bogus Entra passkey enrollment - then registering the attacker's own passkey for persistent access. The weak point is the enrollment moment, not the passkey.

Marcus Chen·8/6/2026·6 min read
A laptop screen displaying code, representing an information-stealing malware attack
Phishing & Social EngineeringThreat Intelligence

Microsoft Warns of ACR Stealer Surge Using ClickFix Lures

Microsoft is warning of a surge in ACR Stealer infections across its enterprise customers, driven by the ClickFix lure that tricks employees into pasting a malicious command themselves. Here is how the attack works - and why the fix is as much about training as it is about tooling.

Marcus Chen·7/19/2026·6 min read
Reviewing employee-reported emails
Threat IntelligenceProduct Updates

Reported Email Review: Turning Employees Into Sensors

When employees report suspicious emails through the empowsec Outlook or Gmail add-in, those reports land in an admin review queue where security teams can classify each one and build real threat intelligence from what is actually reaching inboxes.

Marcus Chen·7/5/2026·8 min read
Reporting a phishing email from Outlook
Phishing & Social EngineeringProduct Updates

Report Phishing from Outlook: The empowsec Add-In Guide

empowsec's Outlook add-in gives employees a one-click 'Report phishing' button in their inbox - capturing email headers and content for review while instantly rewarding employees who correctly identify a simulation.

Marcus Chen·7/3/2026·8 min read
An employee risk score profile
Security Awareness TipsProduct Updates

How the empowsec Employee Risk Scoring Engine Works

empowsec's risk scoring engine assigns weighted points to every phishing and training event, applies time decay so recent behavior matters most, and rolls scores up to department and company level so you can target help where it is actually needed.

Marcus Chen·6/29/2026·8 min read
Employee reviewing an application permission request on a laptop screen
Phishing & Social EngineeringThreat Intelligence

Consent Phishing: Malicious OAuth Apps That Bypass MFA

Consent phishing tricks users into approving a malicious OAuth app — granting attackers token-based access to mail and files without ever touching a password or triggering MFA. Here is how it works and how to shut it down.

Marcus Chen·6/23/2026·6 min read
« Previous123Next »