
Tabletop Exercises: Rehearsing Your Incident Response
A real breach is the worst time to discover that no one knows who decides whether to pay a ransom. Tabletop exercises expose those gaps in a conference room instead of a crisis.
Articles by Marcus Chen

A real breach is the worst time to discover that no one knows who decides whether to pay a ransom. Tabletop exercises expose those gaps in a conference room instead of a crisis.

empowsec tracks every step of a simulated phishing attack - from the pixel that records an open to the fake login form that records a credential submission - and turns each event into a learning opportunity.

Attackers can now clone an executive's voice from three seconds of audio and join a video call as a synthetic colleague. Here's how deepfake CEO fraud works and how to stop it.

empowsec's phishing template library lets you build, translate, import, and export realistic lure emails - so every simulation reaches each employee in their own language.

Phishing simulation campaigns let you measure and improve how your employees respond to real-world lures - safely, at scale, and with the data to prove it is working.

The FBI is warning fans that criminals are spoofing FIFA's ticketing site ahead of the 2026 World Cup. Here is why event-themed lures land in employee inboxes and how to train your team to spot them.

The FBI is warning about Kali365, a phishing-as-a-service platform that hijacks Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass MFA. Here's how the attack works and how to defend your organization.

Device code phishing is spreading through criminal toolkits and phishing-as-a-service offerings. Here is how the Microsoft 365 attack works and what teams should do next.

A new campaign abused Google AppSheet emails to steal Facebook business accounts at scale. Here is what your team should watch for and how empowsec helps build the right response habits.

Our new Google Workspace add-on lets employees report phishing, spam, and suspicious emails with one click — right from their Gmail inbox. Here's how it works and why it matters.

A Chinese national posed as U.S.-based researchers for years, using spear-phishing emails to trick NASA employees and military personnel into handing over restricted aerospace software. The case is a masterclass in why identity verification matters.

A new criminal toolkit called ATHR bundles AI voice agents, phishing emails, and real-time credential harvesting into a single browser-based platform. Here's how vishing-as-a-service is reshaping social engineering and what your organization can do about it.