Featured

All Content

All Tags
All Types
Mette Luntama
Mette Luntama · Sep 14th, 2026
A fake annual performance review, where a QR code hidden inside a PowerPoint attachment quietly bypasses email link scanning to steal Microsoft credentials.
# Phish of the Week
# Phishing
Comment
Mette Luntama
Mette Luntama · Sep 7th, 2026
Attackers turned a fake Docusign signature request into a step-by-step guide for installing malware
# Phish of the Week
# Phishing
Comment
Mette Luntama
Mette Luntama · Aug 31st, 2026
A fake fund-recovery service targets people who already lost money to investment fraud, sent through a real email marketing platform to slip past filters.
# Phish of the Week
# Phishing
Comment
Mette Luntama
Mette Luntama · Aug 24th, 2026
A Google Ads on Air impersonation, where genuine branding, a real third-party mailing platform, and zero urgency combine to make a credential-harvesting page feel routine.
# Phish of the Week
# Phishing
Comment
Mette Luntama
Mette Luntama · Aug 17th, 2026
A fake project collaboration invite, where a calm, urgency-free pretext and a simulated live Teams meeting lull recipients into entering their Microsoft password not once, but twice.
# Phish of the Week
# Phishing
Comment
Laura Lehtiö
Laura Lehtiö · Aug 17th, 2026
How attackers misuse legitimate third-party services to deliver callback phishing, why it's hard to catch, and how to harden your services against it.
# Phishing
# Threat Studies
Comment
Mette Luntama
Mette Luntama · Aug 10th, 2026
A fake charge alert is delivered through VISA's own account-creation system, luring recipients into calling scammers to "cancel" a payment.
# Phish of the Week
# Phishing
Comment
Ant Davis
Ant Davis · Aug 8th, 2026
Security awareness has a low, narrow ceiling and a thin job market. The skills underneath it map almost exactly onto "enablement," a role the market already tracks, prices, and pays for. Here's how to rewrite your CV to reflect that, with real before/after examples.
# Jobs
# Opportunities
# Careers
1
Mette Luntama
Mette Luntama · Aug 3rd, 2026
Attackers are sending out a team lunch RSVP email featuring a genuine Microsoft sign-in link that quietly hands recipients off to a fake Google credential harvester.
# Phish of the Week
# Phishing
Comment
The fourth piece in the Borrowed series, applying ideas from outside security to awareness practice. SaaS companies obsess over getting a new user to their first moment of value within minutes. Security teams hand a new starter a policy document and call it onboarding. This piece applies product activation thinking, the aha moment, time to value, to a new starter's first week.
# Onboarding
# New Starters
Comment