Marcus Chen

Articles by Marcus Chen

Employee seeing an instant training lesson after clicking a simulated phishing email
Phishing & Social EngineeringProduct Updates

Teachable Moments: Just-in-Time Phishing Training on Click

When an employee clicks a simulated phishing link, empowsec turns the mistake into an instant micro-lesson: a Teachable Moment page that explains the exact red flags they just missed, at the moment they are most receptive to learning.

Marcus Chen·8/7/2026·6 min read
Employee receiving an unexpected phone call at an office workstation
Phishing & Social EngineeringThreat Intelligence

Vishing Campaign Abuses Entra Passkey Enrollment Flow

A vishing crew is calling employees as fake Microsoft IT staff and walking them through a bogus Entra passkey enrollment - then registering the attacker's own passkey for persistent access. The weak point is the enrollment moment, not the passkey.

Marcus Chen·8/6/2026·6 min read
A laptop screen displaying code, representing an information-stealing malware attack
Phishing & Social EngineeringThreat Intelligence

Microsoft Warns of ACR Stealer Surge Using ClickFix Lures

Microsoft is warning of a surge in ACR Stealer infections across its enterprise customers, driven by the ClickFix lure that tricks employees into pasting a malicious command themselves. Here is how the attack works - and why the fix is as much about training as it is about tooling.

Marcus Chen·7/19/2026·6 min read
Reviewing employee-reported emails
Threat IntelligenceProduct Updates

Reported Email Review: Turning Employees Into Sensors

When employees report suspicious emails through the empowsec Outlook or Gmail add-in, those reports land in an admin review queue where security teams can classify each one and build real threat intelligence from what is actually reaching inboxes.

Marcus Chen·7/5/2026·8 min read
Reporting a phishing email from Outlook
Phishing & Social EngineeringProduct Updates

Report Phishing from Outlook: The empowsec Add-In Guide

empowsec's Outlook add-in gives employees a one-click 'Report phishing' button in their inbox - capturing email headers and content for review while instantly rewarding employees who correctly identify a simulation.

Marcus Chen·7/3/2026·8 min read
An employee risk score profile
Security Awareness TipsProduct Updates

How the empowsec Employee Risk Scoring Engine Works

empowsec's risk scoring engine assigns weighted points to every phishing and training event, applies time decay so recent behavior matters most, and rolls scores up to department and company level so you can target help where it is actually needed.

Marcus Chen·6/29/2026·8 min read
Employee reviewing an application permission request on a laptop screen
Phishing & Social EngineeringThreat Intelligence

Consent Phishing: Malicious OAuth Apps That Bypass MFA

Consent phishing tricks users into approving a malicious OAuth app — granting attackers token-based access to mail and files without ever touching a password or triggering MFA. Here is how it works and how to shut it down.

Marcus Chen·6/23/2026·6 min read
A simulated phishing landing page used for training
Phishing & Social EngineeringProduct Updates

Phishing Landing Pages, Credential Capture, and Tracking

empowsec tracks every step of a simulated phishing attack - from the pixel that records an open to the fake login form that records a credential submission - and turns each event into a learning opportunity.

Marcus Chen·6/13/2026·7 min read
« Previous12Next »