Featured
# Cybersecurity Awareness Month
Free Cybersecurity Month toolkits, for when you can't build it all

Maxime Cartier
All Content

Mette Luntama · Aug 24th, 2026
A Google Ads on Air impersonation, where genuine branding, a real third-party mailing platform, and zero urgency combine to make a credential-harvesting page feel routine.
# Phish of the Week
# Phishing
Comment

Mette Luntama · Aug 17th, 2026
A fake project collaboration invite, where a calm, urgency-free pretext and a simulated live Teams meeting lull recipients into entering their Microsoft password not once, but twice.
# Phish of the Week
# Phishing
Comment

Laura Lehtiö · Aug 17th, 2026
How attackers misuse legitimate third-party services to deliver callback phishing, why it's hard to catch, and how to harden your services against it.
# Phishing
# Threat Studies
Comment

Mette Luntama · Aug 10th, 2026
A fake charge alert is delivered through VISA's own account-creation system, luring recipients into calling scammers to "cancel" a payment.
# Phish of the Week
# Phishing
Comment

Ant Davis · Aug 8th, 2026
Security awareness has a low, narrow ceiling and a thin job market. The skills underneath it map almost exactly onto "enablement," a role the market already tracks, prices, and pays for. Here's how to rewrite your CV to reflect that, with real before/after examples.
# Jobs
# Opportunities
# Careers
1

Mette Luntama · Aug 3rd, 2026
Attackers are sending out a team lunch RSVP email featuring a genuine Microsoft sign-in link that quietly hands recipients off to a fake Google credential harvester.
# Phish of the Week
# Phishing
Comment

Ant Davis · Aug 3rd, 2026
The fourth piece in the Borrowed series, applying ideas from outside security to awareness practice. SaaS companies obsess over getting a new user to their first moment of value within minutes. Security teams hand a new starter a policy document and call it onboarding. This piece applies product activation thinking, the aha moment, time to value, to a new starter's first week.
# Onboarding
# New Starters
Comment

Mette Luntama · Jul 27th, 2026
This Phish of the Week features a personalized Adobe Summit invitation with mismatched event dates and a countdown timer that pressures recipients into signing in through a fake Google pop-up.
# Phish of the Week
# Phishing
Comment

Ant Davis · Jul 27th, 2026
The third piece in the Borrowed series, applying ideas from outside security to awareness practice. Marketing solved audience segmentation decades ago, but security awareness still sends the same simulation to every department regardless of what an attacker would actually want from that team. This piece applies real segmentation, by risk exposure, technical fluency, and workflow, to phishing simulations and comms.
# Phishing
Comment

Ant Davis · Jul 20th, 2026
The second piece in the Borrowed series, applying ideas from outside security to awareness practice. Ebbinghaus's forgetting curve and Cepeda's research on spaced practice explain why one big annual session, or even quarterly, was never going to hold. This piece breaks down the memory science behind why training fades and what genuine reinforcement looks like instead.
# Security Awareness Training
2

