#employee training

Security awareness tips, industry news, and product updates.

Hands-on interactive security exercises
Security Awareness TipsProduct Updates

Interactive Training Page Types in empowsec: Part 2

Part 2 of empowsec's interactive page types covers the hands-on practice formats: click-to-match, ordering, fill in the blanks, email red-flag finder, and chat simulation - each designed to make learners practice the skill, not just read about it.

Sarah Mitchell·6/19/2026·9 min read
An interactive security training lesson
Security Awareness TipsProduct Updates

Interactive Training Page Types in empowsec: Part 1

empowsec training is built from interactive page types - not static slides. Part 1 introduces seven of them, from simple info pages and accordions to graded quizzes, scenarios, and drag-to-match exercises.

Sarah Mitchell·6/17/2026·8 min read
Employee entering a login code on a laptop at an office desk
Phishing & Social EngineeringSecurity Awareness TipsThreat Intelligence

Kali365 Phishing Service Targets Microsoft 365 Accounts

The FBI is warning about Kali365, a phishing-as-a-service platform that hijacks Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass MFA. Here's how the attack works and how to defend your organization.

Marcus Chen·6/6/2026·9 min read
Security analyst reviewing a suspicious device login code on a laptop
Phishing & Social EngineeringSecurity Awareness TipsThreat Intelligence

Device Code Phishing Is Moving Into Criminal Toolkits

Device code phishing is spreading through criminal toolkits and phishing-as-a-service offerings. Here is how the Microsoft 365 attack works and what teams should do next.

Marcus Chen·5/15/2026·8 min read
Security team reviewing a suspicious compliance email on a laptop
Phishing & Social EngineeringSecurity Awareness TipsThreat Intelligence

Microsoft AiTM Phishing Alert: Lessons for US Teams

Microsoft is warning US organizations about a sophisticated code-of-conduct phishing campaign using PDFs, CAPTCHA gates, and AiTM token theft. Here is what security teams should watch for next.

Rachel Andersen·5/6/2026·7 min read
Marketing employee reviewing a social media account alert on a laptop
Phishing & Social EngineeringSecurity Awareness TipsThreat Intelligence

Facebook Phishing Through Google: What Teams Should Do

A new campaign abused Google AppSheet emails to steal Facebook business accounts at scale. Here is what your team should watch for and how empowsec helps build the right response habits.

Marcus Chen·5/5/2026·7 min read
A colorful party invitation envelope being opened, symbolizing a potential phishing scam
Phishing & Social EngineeringSecurity Awareness Tips

Fake Party Invitations Are the Newest Phishing Trap

Cybercriminals are spoofing Paperless Post, Evite, and Punchbowl to send fake party invitations that exploit your fear of missing out. Here's how the scam works and how to protect yourself.

Rachel Andersen·4/29/2026·7 min read
Employee taking a suspicious phone call while working at a laptop
Phishing & Social EngineeringSecurity Awareness TipsThreat Intelligence

ATHR Vishing-as-a-Service: AI Voice Scams Go Plug and Play

A new criminal toolkit called ATHR bundles AI voice agents, phishing emails, and real-time credential harvesting into a single browser-based platform. Here's how vishing-as-a-service is reshaping social engineering and what your organization can do about it.

Marcus Chen·4/19/2026·10 min read