News

Security awareness tips, industry news, and product updates.

A training manager customizing an e-learning course on a laptop
Security Awareness TipsProduct Updates

How to Fork and Customize Training Courses in empowsec

empowsec lets companies and resellers fork any global course into an editable copy - quizzes, interactive pages, and settings included - then sync with upstream updates or delete the fork to revert, while learners always see the most specific version.

Elena Vasquez·8/18/2026·6 min read
An MSP account manager reviewing consolidated client analytics on a screen
For MSPs & PartnersProduct Updates

Consolidated Training and Phishing Reports for MSPs

empowsec reseller analytics roll every client company into one view: training completion, phishing click, open, report, and reply rates, per-company risk, and CSV or PDF exports - the numbers an MSP needs for a QBR without logging into thirty tenants.

Thomas Eriksson·8/17/2026·5 min read
Exterior of a modern law firm office building where professional-services firms operate
Phishing & Social EngineeringThreat Intelligence

Luna Moth Escalates: FBI Alert, Leak Site, $20M Demands

The Luna Moth extortion crew escalated sharply in May and June 2026: an FBI FLASH alert, a leak site listing roughly 100 victims, reported $20 million ransom demands and attackers walking into law firm offices in person.

Sarah Mitchell·8/17/2026·6 min read
German office building representing NIS2-regulated entities facing the BSI enforcement phase
Compliance & RegulationsFor MSPs & Partners

Germany NIS2: Grace Deadline Expired, Enforcement Begins

The BSI's final grace deadline for NIS2 registration expired on 31 July 2026 with thousands of in-scope German entities still unregistered. Germany's NIS2 regime now enters its enforcement phase, and registration failures alone can draw fines of up to EUR 500,000.

David Kowalski·8/16/2026·5 min read
A manager configuring access permissions for team members on a laptop
Compliance & RegulationsProduct Updates

Custom Roles and Granular Permissions in empowsec Explained

empowsec lets company admins build custom roles with granular permissions, renders a dashboard with only the tabs each user may see, and gives reseller teams an equivalent permission system - so nobody needs full admin access just to do one job.

David Kowalski·8/15/2026·7 min read
Tax forms and a calculator on a desk during tax filing season
Phishing & Social EngineeringSecurity Awareness Tips

ELSTER Tax Phishing Wave Hits Germany in Summer 2026

US tax-authority phishing surged over 400 percent in 2026, and fake ELSTER refund mails are landing while German employees file their 2025 returns. The core lesson for staff: the Finanzamt never emails your refund.

Natalie Hoffmann·8/15/2026·5 min read
Employee using an AI chatbot assistant on a laptop in an office
Phishing & Social EngineeringSecurity Awareness Tips

AI Brand Phishing: ChatGPT, Copilot and Claude as Lures

Microsoft has documented phishing campaigns impersonating ChatGPT, Copilot, Claude, and DeepSeek - lures built for employees who use AI tools every day. It is a new template family your simulations should cover.

Thomas Eriksson·8/14/2026·5 min read
HR and IT team reviewing an automated training enrollment plan
Compliance & RegulationsProduct Updates

Automated Recurring Training Enrollment for Compliance

Compliance frameworks expect regular, evidenced security training - but manual re-enrollment does not scale. empowsec automation rules enroll new hires automatically and re-run courses every 3, 6, 12 or 24 months, hands-off.

Rachel Andersen·8/14/2026·5 min read
Mail server infrastructure powering authenticated phishing simulation delivery
Phishing & Social EngineeringProduct Updates

Dedicated Sending and Tracking Domains for Phishing Tests

Realistic phishing simulations only work if the emails actually arrive. empowsec provisions a dedicated, fully authenticated sending domain for every company in one click - SPF, DKIM and DMARC included - and tells you exactly which IPs to allow-list.

Sarah Mitchell·8/12/2026·5 min read
Professional reviewing artificial intelligence transparency requirements on a screen in a European office
Compliance & RegulationsThreat Intelligence

EU AI Act August 2026: What Changed and What Was Delayed

The Digital Omnibus postponed the AI Act's high-risk regime, but the Article 50 transparency duties applied on schedule from 2 August 2026. Chatbot disclosure, deepfake labeling, and emotion-recognition notices are now enforceable, and security teams have work to do.

Elena Vasquez·8/11/2026·6 min read