#email security

Security awareness tips, industry news, and product updates.

Laptop screen showing an email inbox with file attachments
Phishing & Social EngineeringThreat Intelligence

SVG Attachment Phishing Surges Fifty-Fold, Research Finds

New 2026 research shows malicious SVG attachments have grown fifty-fold, becoming the third most common malicious attachment type. Here is why an image file can phish you - and what to change in your filters, policies and simulations.

Rachel Andersen·8/19/2026·5 min read
Mail server infrastructure powering authenticated phishing simulation delivery
Phishing & Social EngineeringProduct Updates

Dedicated Sending and Tracking Domains for Phishing Tests

Realistic phishing simulations only work if the emails actually arrive. empowsec provisions a dedicated, fully authenticated sending domain for every company in one click - SPF, DKIM and DMARC included - and tells you exactly which IPs to allow-list.

Sarah Mitchell·8/12/2026·5 min read
Empty office desk with a closed laptop during the summer vacation period
Phishing & Social EngineeringSecurity Awareness Tips

Out-of-Office Replies Are a Gift to Attackers in August

Detailed out-of-office auto-replies hand attackers absence dates, deputy contacts, and reporting lines - exactly when SOC staffing is thinnest. How to write OOO messages that say less, and why August deserves its own simulation.

Lisa Brennan·8/9/2026·6 min read
Setting up two-factor authentication
Security Awareness TipsProduct Updates

Stronger Logins with TOTP Two-Factor Authentication

empowsec supports time-based one-time password (TOTP) two-factor authentication so that even a stolen password cannot open an account. Here is how it works and why it matters for every security-conscious organization.

David Kowalski·7/17/2026·6 min read
Free online security tools from empowsec
Security Awareness TipsProduct Updates

empowsec Free Security Tools Suite: Eight Tools, No Login

empowsec offers eight free public security tools - no account required. From password strength testing to live email authentication checks, these tools give anyone a quick way to spot weaknesses and illustrate the kind of awareness empowsec builds across an entire organization.

Sarah Mitchell·7/11/2026·9 min read
Reviewing employee-reported emails
Threat IntelligenceProduct Updates

Reported Email Review: Turning Employees Into Sensors

When employees report suspicious emails through the empowsec Outlook or Gmail add-in, those reports land in an admin review queue where security teams can classify each one and build real threat intelligence from what is actually reaching inboxes.

Marcus Chen·7/5/2026·8 min read
Reporting a phishing email from Outlook
Phishing & Social EngineeringProduct Updates

Report Phishing from Outlook: The empowsec Add-In Guide

empowsec's Outlook add-in gives employees a one-click 'Report phishing' button in their inbox - capturing email headers and content for review while instantly rewarding employees who correctly identify a simulation.

Marcus Chen·7/3/2026·8 min read
Close inspection of a web address on a laptop screen with a magnifying glass
Phishing & Social EngineeringThreat Intelligence

Lookalike Domains & Typosquatting: A Defense Guide

An 'rn' that reads as an 'm', an extra word, a wrong TLD — lookalike domains impersonate trusted brands in phishing and brand abuse. Here is how to spot them and the controls that blunt them.

David Kowalski·6/22/2026·7 min read
A simulated phishing landing page used for training
Phishing & Social EngineeringProduct Updates

Phishing Landing Pages, Credential Capture, and Tracking

empowsec tracks every step of a simulated phishing attack - from the pixel that records an open to the fake login form that records a credential submission - and turns each event into a learning opportunity.

Marcus Chen·6/13/2026·7 min read
« Previous12Next »