Read articles about security awareness, risk management, behavior change, and more
How quishing is being used in attacks, what these threats look like in the wild and best practices for avoiding them.
Discover how Hoxhunt outperforms competitors in cybersecurity training. Based on real reviews, compare Hoxhunt's features, quality, and effectiveness to leading alternatives.
A deep dive into the top Proofpoint competitors and alternatives for effective security awareness training to find the best fit for your organization.
Learn how to prevent smishing with these 7 best practices. Your ultimate guide to how smishing works, what attacks look like and how to protect your business.
Empower your team to be a human firewall. Discover how training, vigilance, and smart habits protect against cyber threats.
The top KnowBe4 competitors to consider for security awareness and phishing training. Compare features, personalization, analytics, and more to make the right choice for your organization.
TikTok's open redirection vulnerability is being used in phishing emails. Here's what we know and how to prevent successful attacks.
Fantasy football can teach us how to learn stop worrying and love the art and chaos of starting a new leadership position.
Recent research published in the wall street was correct: bad phishing simulations produce bad results. So what now?
The CISO Fantasy Phish Bowl 2025 brings together some old friends and new joiners. There's one heavy absence: Shawn Bowen, to whom this year's Phish Bowl is dedicated. Here's to you, Shawn!
Phishing simulation best practices with real case results from Bird & Bird - ethical lures, instant feedback, and KPIs that drive reporting.
Best phishing simulation tools for enterprises (2025) - AI-powered, gamified platforms with multi-vector realism, SOC integrations, and risk dashboards.
Cybersecurity Awareness Month ideas that work: run a focused 10-day campaign, launch phishing simulations, boost MFA adoption, and use our 2025 toolkit.
Frost & Sullivan spotlighted Hoxhunt for transforming human risk in cybersecurity. Their report shows a 225% increase in phishing reporting and 3X fewer clicks.
Why cyber insurance needs human risk management platforms and so do you
Your ultimate guide on how to prevent phishing. Everything you need to know to implement best practices and set up training that measurably reduces risk.
Your ultimate guide to spam vs phishing. What the differences are, how to recognize them and all of the practical measures you can take to keep your organization safe.
What is an SOC report? What are the different types of SOC reports available? How do you obtain one? Your questions answered.
We'll look into the behaviors to watch out for, how to assess risk and all the strategies you need to tangibly reduce human risk across your organization.
Repeat phishing offenders aren’t the problem... static training is. Learn how we use adaptive simulations to convert clickers into security assets.
Here's how to change the narrative around cybersecurity to get employees engaged.
How do you achieve cybersecurity behavior change? A breakdown of how science-based training transforms awareness into real-world risk reduction.
Learn how behavior-based cyber security training drives lasting employee behavior change. A breakdown of the key components, benefits, and why it’s essential for building a strong security culture.
The evolution of malware into today's most brutal phishing techniques has been guided by social engineering. Here's how and why.
Recruitment scams happen when a malicious actor claims to be a recruiting agent for a job that does not really exist
Loan scam emails prey on financial uncertainty and even pandemic desperation as businesses and individuals look for financial relief anywhere they can find it.
Copyright infringement phishing attacks can seem legit by burying threats of legal action inside a bunch of legalese citing legal statutes with financial penalties.
Cybercriminals are taking a page from the annals of rigged sports gambling, offering a little cash in return for a much bigger pay-off. This new phishing tactic plays on workforce disgruntlement to turn employees into insider threats with the exchange of bribes for complicity in a ransomware attack.
Open Redirects help attackers spoof legitimate brand URLs in their phishing attacks.
Your SaaS suite is leaving your backdoor open. Here's how to fix it.
Log4J Log4Shell vulnerability explained to help you understand what it is and how to stay protected
A security vulnerability was recently reported in the default guest permissions of Microsoft Azure Active Directory. Here’s how to fix it and stay safe from attackers.
This phishing email was sent from outside the organization but is replacing the Caution! External Sender banner with a safe sender banner.
Apple just recently confirmed the most significant vulnerability in iOS history after ZecOps made a public announcement about their discovery of a security flaw.
According to security researchers, the iOS mail app, which is the email client that can be found on most Apple iPhones and iPads, has a severe security flaw making it vulnerable to attacks.
Years later, pop-ups are back, this time serving a different purpose... stealing your info.
The more digital money you make, the more digital problems you get. Here's some tips to keep your crypto wallet safe.
Phishing campaigns can hijack legitimate services like Microsoft or Adobe to bypass spam filters and earn user trust
Attackers often craft phishing campaigns based on data they find online about the victims. Why would you miss out on personalizing your phishing training?
Learn about the most common social engineering tactics that attackers use to bypass two-factor authentication.
How to prepare your employees to recognize social engineering? We'll explain what it is and what you need to do shield your company from social engineering.