Lookout, Inc. today announced the launch of Lookout Social Engineering Protection (SEP). Integrated directly into the Lookout Mobile AI Security Platform, the new module delivers automated, real-time protection against the next generation of AI-driven mobile threats, including synthetic voice cloning, deepfake vishing, executive impersonation, and linkless smishing attacks.
Frontier AI is transforming social engineering by enabling attackers to create highly convincing deception with unprecedented realism, personalization, and scale. Advanced AI models can craft context-aware messages tailored to individual employees, while advanced voice cloning and deepfake technologies can convincingly impersonate executives, colleagues, and IT support. These capabilities make it increasingly difficult for employees to distinguish legitimate communications from malicious ones. As critical business interactions increasingly move to SMS, voice calls, WhatsApp, and other mobile channels, mobile has become a primary attack surface for AI-powered deception.
Legacy defenses were not designed for this new generation of AI-powered deception. Email security largely protects a single channel and often relies on detecting malicious links, attachments, and known indicators, while Security Awareness Training depends on employees recognizing increasingly sophisticated attacks themselves. Neither approach can keep pace with highly personalized, convincing attacks that span SMS, voice, and messaging applications. This new threat demands a more sophisticated approach—one that can continuously analyze the intent, context, and authenticity of mobile interactions in real time. Lookout Social Engineering Protection delivers that protection across mobile channels.
Omnichannel Defense Against Mobile Deception
Lookout Social Engineering Protection delivers AI-powered, multi-channel defense across text and voice communications:
- Smishing Protection: Continuously analyzes incoming SMS, MMS, and RCS messages on iOS and Android to detect malicious links, phishing attempts, and suspicious intent in real time.
- Vishing Protection: Analyzes audio and voicemail to detect AI-generated voice clones and deepfakes, while transcribing conversations to identify suspicious intent and scam patterns.
- Phone Number Authentication & Centralized Call Blocking: Uses mobile identity signals and phone-number attributes to distinguish legitimate callers from numbers exhibiting suspicious characteristics or behaviors, enabling organizations to apply risk-based controls and centrally block known or suspicious numbers across the mobile workforce.
Addressing the Mobile AI Risk Triangle
With the launch of Social Engineering Protection, Lookout introduces the third core pillar of its Mobile AI Security Platform, delivering continuous protection across three critical areas of mobile risk: AI usage and data exposure, mobile software vulnerabilities, and AI-powered human manipulation.
- AI Visibility & Governance: Protects enterprise data by providing visibility and control over employee interactions with generative, agentic, and Shadow AI applications.
- Mobile Software Exposure Center (MSEC): Reduces mobile software risk by continuously identifying vulnerable components, SDKs, and libraries embedded within compiled mobile applications.
- Social Engineering Protection (SEP): Protects employees from AI-powered deception by detecting and stopping smishing, vishing, voice cloning, and other sophisticated social engineering attacks in real time.
Availability
Lookout Social Engineering Protection is available as a native add-on module for the Lookout Mobile AI Security Platform. Existing customers can activate SEP capabilities directly in their unified admin console, without additional agents or infrastructure.
Exclaimer helps customers meet WCAG 2.1 AA accessibility requirements for email signatures
Posted in Commentary with tags Exclaimer on September 23, 2026 by itnerdExclaimer today announced the launch of Accessibility Controls, a collection of new and existing functionalities within Exclaimer that teams can use to ensure templates satisfy 28 WCAG 2.1 Level AA success criteria that apply to email signature content.
Most organizational accessibility work targets websites and apps. Email signatures are usually left out, even though they go out thousands of times a day and reach more external stakeholders directly than almost any other communication channel. In an email signature, something as simple as missing screen reader labels where links provide no context, missing alt text, or contact details embedded as an image rather than text can make important information inaccessible to someone using a screen reader.
For public sector and federally funded organizations in the US, accessibility requirements are becoming more prescriptive. The Department of Justice’s ADA Title II rule requires state and local government web content and mobile apps to meet WCAG 2.1 Level AA, with entities serving populations of 50,000 or more required to comply by April 26, 2027, and smaller entities and special district governments by April 26, 2028. Separately, organizations receiving HHS funding with 15 or more employees have until May 11, 2027, to bring web content and mobile apps into conformance with WCAG 2.1 Level AA under Section 504, while smaller recipients have until May 10, 2028. These rules do not set specific deadlines for email signatures, but they reflect growing regulatory focus on how organizations make digital information accessible.
How Accessibility Controls work
Exclaimer’s Accessibility Controls covers four capabilities inside the signature designer, some automatic and some configured by the template owner:
1. Semantic structure. Signatures are built and output as structured, readable content rather than a table, so screen readers announce information in the order it’s laid out.
2. Screen reader (ARIA) labels. Interactive elements like hyperlinks can carry a descriptive label, so a screen reader says “Book a demo with our team” instead of “link.”
3. Language declaration. Signatures can declare their language so screen readers use correct pronunciation, useful for organizations sending signatures in more than one language.
4. Clickable QR codes. QR codes in a signature are made more clickable, giving recipients who can’t or don’t want to scan a code a working path to the same destination.
These sit alongside existing controls: alt text set centrally at the template level, Brand Kits that keep approved color combinations and accessible fonts at or above WCAG’s minimum 4.5:1 contrast ratio for standard text, and text that renders as real HTML rather than an image, so it can be resized and read aloud.
A first for email signature management
Of the 50 Level A and AA success criteria in WCAG 2.1, 28 apply to content like an email signature. Exclaimer is the first and only email signature management provider to offer native functionality addressing all 28, without requiring customers to write HTML.
Set at the template level, Accessibility Controls apply across an organization’s email signatures in Microsoft 365 and Google Workspace as soon as a template is published, with no need to touch individual employee signatures.
Availability
Accessibility Controls is available now within the Exclaimer signature designer, as part of Exclaimer’s existing plans, for customers on Microsoft 365 and Google Workspace.
Leave a comment »