#social engineering

Security awareness tips, industry news, and product updates.

Group of new employees arriving at the office together at the start of September
Phishing & Social EngineeringSecurity Awareness Tips

New Hires, September Starts: The 90-Day Phishing Window

September brings the year's biggest wave of new starters - and attackers time their CEO impersonation campaigns to match. Why the first 90 days are the most phishable window of any tenure, and how to protect the whole incoming cohort.

Daniel Okafor·8/31/2026·5 min read
New York financial district offices representing NYDFS-regulated entities subject to Part 500 training requirements
Phishing & Social EngineeringCompliance & Regulations

NYDFS Vishing Advisory: Part 500 Training Expectations

NYDFS has told regulated financial entities, in writing, to train staff against help-desk vishing attacks. Combined with the fully effective Part 500 amendment and a record enforcement run, targeted social-engineering training is now a supervisory expectation in New York.

Rachel Andersen·8/24/2026·5 min read
Empty office desk with a closed laptop during the summer vacation period
Phishing & Social EngineeringSecurity Awareness Tips

Out-of-Office Replies Are a Gift to Attackers in August

Detailed out-of-office auto-replies hand attackers absence dates, deputy contacts, and reporting lines - exactly when SOC staffing is thinnest. How to write OOO messages that say less, and why August deserves its own simulation.

Lisa Brennan·8/9/2026·6 min read
Employee receiving an unexpected phone call at an office workstation
Phishing & Social EngineeringThreat Intelligence

Vishing Campaign Abuses Entra Passkey Enrollment Flow

A vishing crew is calling employees as fake Microsoft IT staff and walking them through a bogus Entra passkey enrollment - then registering the attacker's own passkey for persistent access. The weak point is the enrollment moment, not the passkey.

Marcus Chen·8/6/2026·6 min read
A laptop screen displaying code, representing an information-stealing malware attack
Phishing & Social EngineeringThreat Intelligence

Microsoft Warns of ACR Stealer Surge Using ClickFix Lures

Microsoft is warning of a surge in ACR Stealer infections across its enterprise customers, driven by the ClickFix lure that tricks employees into pasting a malicious command themselves. Here is how the attack works - and why the fix is as much about training as it is about tooling.

Marcus Chen·7/19/2026·6 min read
Office worker on a laptop video call reviewing a chat message in a collaboration app
Phishing & Social EngineeringThreat Intelligence

Teams & Slack Phishing: The Threat Beyond the Inbox

Phishing has moved out of the inbox and into Microsoft Teams, Slack, and calendar invites — platforms employees trust by default. Here is how the attacks work and how to extend your defenses to cover them.

Elena Vasquez·6/26/2026·7 min read
An employee reading an urgent text message on a smartphone at work
Phishing & Social Engineering

Gift Card Scams: The "Are You Available?" CEO Fraud

"Are you available? I need a quick favor." It's the opening line of a gift card scam impersonating your CEO - low-tech, high-volume, and aimed at new and junior staff. Here's the pattern and the one rule that stops it.

Thomas Eriksson·6/25/2026·7 min read
« Previous123Next »