#MFA

Security awareness tips, industry news, and product updates.

Employee receiving an unexpected phone call at an office workstation
Phishing & Social EngineeringThreat Intelligence

Vishing Campaign Abuses Entra Passkey Enrollment Flow

A vishing crew is calling employees as fake Microsoft IT staff and walking them through a bogus Entra passkey enrollment - then registering the attacker's own passkey for persistent access. The weak point is the enrollment moment, not the passkey.

Marcus Chen·8/6/2026·6 min read
Setting up two-factor authentication
Security Awareness TipsProduct Updates

Stronger Logins with TOTP Two-Factor Authentication

empowsec supports time-based one-time password (TOTP) two-factor authentication so that even a stolen password cannot open an account. Here is how it works and why it matters for every security-conscious organization.

David Kowalski·7/17/2026·6 min read
University students working on laptops on a busy campus
Security Awareness TipsThreat Intelligence

Education Under Siege: Lessons From the Canvas Breach

ShinyHunters' May 2026 breach of the Canvas LMS exposed data tied to thousands of schools and hundreds of millions of users. Here is why education is a prime target and how awareness training reduces the risk.

James Thornton·7/1/2026·6 min read
Employee reviewing an application permission request on a laptop screen
Phishing & Social EngineeringThreat Intelligence

Consent Phishing: Malicious OAuth Apps That Bypass MFA

Consent phishing tricks users into approving a malicious OAuth app — granting attackers token-based access to mail and files without ever touching a password or triggering MFA. Here is how it works and how to shut it down.

Marcus Chen·6/23/2026·6 min read
« Previous12Next »