Archive for September 23, 2026

Exclaimer helps customers meet WCAG 2.1 AA accessibility requirements for email signatures

Posted in Commentary with tags on September 23, 2026 by itnerd

Exclaimer today announced the launch of Accessibility Controls, a collection of new and existing functionalities within Exclaimer that teams can use to ensure templates satisfy 28 WCAG 2.1 Level AA success criteria that apply to email signature content.

Most organizational accessibility work targets websites and apps. Email signatures are usually left out, even though they go out thousands of times a day and reach more external stakeholders directly than almost any other communication channel. In an email signature, something as simple as missing screen reader labels where links provide no context, missing alt text, or contact details embedded as an image rather than text can make important information inaccessible to someone using a screen reader.

For public sector and federally funded organizations in the US, accessibility requirements are becoming more prescriptive. The Department of Justice’s ADA Title II rule requires state and local government web content and mobile apps to meet WCAG 2.1 Level AA, with entities serving populations of 50,000 or more required to comply by April 26, 2027, and smaller entities and special district governments by April 26, 2028. Separately, organizations receiving HHS funding with 15 or more employees have until May 11, 2027, to bring web content and mobile apps into conformance with WCAG 2.1 Level AA under Section 504, while smaller recipients have until May 10, 2028. These rules do not set specific deadlines for email signatures, but they reflect growing regulatory focus on how organizations make digital information accessible.

How Accessibility Controls work

Exclaimer’s Accessibility Controls covers four capabilities inside the signature designer, some automatic and some configured by the template owner:

1. Semantic structure. Signatures are built and output as structured, readable content rather than a table, so screen readers announce information in the order it’s laid out.

2. Screen reader (ARIA) labels. Interactive elements like hyperlinks can carry a descriptive label, so a screen reader says “Book a demo with our team” instead of “link.”

3. Language declaration. Signatures can declare their language so screen readers use correct pronunciation, useful for organizations sending signatures in more than one language.

4. Clickable QR codes. QR codes in a signature are made more clickable, giving recipients who can’t or don’t want to scan a code a working path to the same destination.

These sit alongside existing controls: alt text set centrally at the template level, Brand Kits that keep approved color combinations and accessible fonts at or above WCAG’s minimum 4.5:1 contrast ratio for standard text, and text that renders as real HTML rather than an image, so it can be resized and read aloud.

A first for email signature management

Of the 50 Level A and AA success criteria in WCAG 2.1, 28 apply to content like an email signature. Exclaimer is the first and only email signature management provider to offer native functionality addressing all 28, without requiring customers to write HTML.

Set at the template level, Accessibility Controls apply across an organization’s email signatures in Microsoft 365 and Google Workspace as soon as a template is published, with no need to touch individual employee signatures.

Availability

Accessibility Controls is available now within the Exclaimer signature designer, as part of Exclaimer’s existing plans, for customers on Microsoft 365 and Google Workspace.

Lookout Unveils Social Engineering Protection

Posted in Commentary with tags on September 23, 2026 by itnerd

Lookout, Inc. today announced the launch of Lookout Social Engineering Protection (SEP). Integrated directly into the Lookout Mobile AI Security Platform, the new module delivers automated, real-time protection against the next generation of AI-driven mobile threats, including synthetic voice cloning, deepfake vishing, executive impersonation, and linkless smishing attacks.

Frontier AI is transforming social engineering by enabling attackers to create highly convincing deception with unprecedented realism, personalization, and scale. Advanced AI models can craft context-aware messages tailored to individual employees, while advanced voice cloning and deepfake technologies can convincingly impersonate executives, colleagues, and IT support. These capabilities make it increasingly difficult for employees to distinguish legitimate communications from malicious ones. As critical business interactions increasingly move to SMS, voice calls, WhatsApp, and other mobile channels, mobile has become a primary attack surface for AI-powered deception.

Legacy defenses were not designed for this new generation of AI-powered deception. Email security largely protects a single channel and often relies on detecting malicious links, attachments, and known indicators, while Security Awareness Training depends on employees recognizing increasingly sophisticated attacks themselves. Neither approach can keep pace with highly personalized, convincing attacks that span SMS, voice, and messaging applications. This new threat demands a more sophisticated approach—one that can continuously analyze the intent, context, and authenticity of mobile interactions in real time. Lookout Social Engineering Protection delivers that protection across mobile channels.

Omnichannel Defense Against Mobile Deception

Lookout Social Engineering Protection delivers AI-powered, multi-channel defense across text and voice communications:

  • Smishing Protection: Continuously analyzes incoming SMS, MMS, and RCS messages on iOS and Android to detect malicious links, phishing attempts, and suspicious intent in real time.
  • Vishing Protection: Analyzes audio and voicemail to detect AI-generated voice clones and deepfakes, while transcribing conversations to identify suspicious intent and scam patterns.
  • Phone Number Authentication & Centralized Call Blocking: Uses mobile identity signals and phone-number attributes to distinguish legitimate callers from numbers exhibiting suspicious characteristics or behaviors, enabling organizations to apply risk-based controls and centrally block known or suspicious numbers across the mobile workforce.

Addressing the Mobile AI Risk Triangle

With the launch of Social Engineering Protection, Lookout introduces the third core pillar of its Mobile AI Security Platform, delivering continuous protection across three critical areas of mobile risk: AI usage and data exposure, mobile software vulnerabilities, and AI-powered human manipulation.

  • AI Visibility & Governance: Protects enterprise data by providing visibility and control over employee interactions with generative, agentic, and Shadow AI applications.
  • Mobile Software Exposure Center (MSEC): Reduces mobile software risk by continuously identifying vulnerable components, SDKs, and libraries embedded within compiled mobile applications.
  • Social Engineering Protection (SEP): Protects employees from AI-powered deception by detecting and stopping smishing, vishing, voice cloning, and other sophisticated social engineering attacks in real time.

Availability

Lookout Social Engineering Protection is available as a native add-on module for the Lookout Mobile AI Security Platform. Existing customers can activate SEP capabilities directly in their unified admin console, without additional agents or infrastructure.

AI-native patent firm Fearn launches to take on the billable hour in a $14B market

Posted in Commentary with tags on September 23, 2026 by itnerd

A conventional patent application can take 30 to 40 hours of attorney time, cost $18,000 to $40,000 in legal fees, while startups wait months to protect technology that can change by the day. Fearn, the modern patent prosecution firm for startups, was built around a different model.

Today, the company launched an AI-native patent firm pairing former Big Law patent experts with an in-house AI and engineering team. Fearn drafts and prosecutes patents across software, hardware, robotics, semiconductors, defense, biotech and pharma, with fixed fees, provisional filings in as little as three business days, and a guarantee that puts its drafting fee at risk if a non-provisional application receives no allowed claims.

The company has raised $5.5 million from Kindred Ventures, a16z Speedrun, Designer Fund and Essence VC. Fearn enters a  $14 billion global patent market, with early-stage companies filing 150,000 new patent applications every year.

The journey 

Fearn was founded by Caltech alumni Han Kim and Angela Gao after they saw the same problem from opposite sides. Kim had prosecuted patents at Morrison & Foerster, while Gao earned a PhD in computer science and AI. They initially built software for law firms, but quickly realized better tooling alone would not fix a model where time saved meant revenue lost and sensitive pre-filing IP made AI difficult to deploy safely.

So they built the firm around the technology instead. Today, Fearn has hundreds of users, from venture-backed startups to public companies. 

How Fearn works  

At the center of the firm is FearnOS, its proprietary drafting and client management system. Instead of treating a patent as one long linear document, it represents the patent as a graph: it maps claims to the supporting text, figures and technical material behind them, while preserving attorney edits and a full record of how each section was produced.

That structure lets Fearn combine specialized AI with deterministic checks without taking the patent professional out of the loop. Every application is still reviewed by a former Big Law patent expert.

Fearn says work that typically takes 30 to 40 attorney hours can require as little as 30 minutes of attorney time on FearnOS. Provisionals cost $2,500, non-provisionals $9,000 including USPTO fees, and the firm reports gross margins above 80%.

Clients also manage their portfolio through the platform, with controlled access to individual patents, a complete version history and secure connections to the places where technical documentation already lives.

Customer outcomes

Fearn is already being used across technically demanding industries where filing speed can determine whether valuable IP is protected before a product demo, publication or competitive breakthrough.

London-based game studio Iconic went from invention disclosures to filed applications in days while protecting technology for AI characters that improvise in real time. American defense technology company Photon Spear used Fearn to file a hardware space technology patent in several days while keeping its material entirely on privately hosted infrastructure. Serova Bio uses the platform for patent work around AI-designed personalized cancer vaccines, where claims, supporting disclosure and a growing portfolio need to remain coordinated as the underlying science evolves.

The broader legal market is moving in the same direction. Major firms are making unusually large investments in proprietary AI infrastructure precisely because sensitive legal work requires more control over models and client data. Fearn’s thesis is that startups should be able to access that level of technical infrastructure without inheriting the economics and operating model of Big Law.

What’s next

Fearn’s ambition goes beyond drafting patents faster. It wants to give startups the kind of portfolio strategy once reserved for companies with large in-house IP teams and seven-figure outside-counsel budgets. The company is extending FearnOS across patent families, international filings, office actions and long-term portfolio strategy, so founders can see what protects each product, where coverage is weak and what should be filed next.

The end goal is simple: give a three-person startup the patent infrastructure of a much larger company, so the strength of its IP depends more on what it invented than what it can afford to spend protecting it.

Guest Post: “ClickFix” — a new wave of social engineering

Posted in Commentary with tags on September 23, 2026 by itnerd

The security industry keeps raising the bar on authentication, yet the weakest link is still the human — and with ClickFix attacks, hackers have found a way to make people hack themselves.

ClickFix is a social engineering attack where the victim is tricked into running malicious code on their own machine, thus giving the threat actor access to everything, including their saved passwords, passkeys, and session cookies.

A real case study

“Someone recently contacted me with a simple question: ‘Is my computer infected?’ For the record, he’s not a NordPass user — he found me through my personal website. He’d come across a LinkedIn post about ClickFix attacks and realized that, just a week earlier, he’d probably fallen victim to one himself. He was right. His story is worth telling — because everything about it looks harmless until the very last second,” says Deividas Ambrazevicius, an engineering manager at NordPass.

The man asking for help was chatting with a former colleague about a week earlier — a real person he knew, with years of message history between them. Or so he thought. This “former colleague” proposed a call, claiming he wanted to talk about work. However, the call failed — no audio — so he said that Microsoft Teams probably needed an update and sent a tidy set of instructions. Where to go, what to copy, where to paste — all neatly prepared. The man followed every step. Then “the colleague” disappeared. And a week later, doubts set in. 

Ambrazevicius suggested reaching out to the person in question through another channel — such as LinkedIn. And sure enough, the colleague knew nothing about any of it. His account had been hijacked. 

“I extracted the relevant data from the computer and ran a forensic analysis. What I found included both the malicious traces and pieces of the story of how the attack unfolded,” says Ambrazevicius.

  • The code was obfuscated at the individual character level, so a simple text search would not find it. 
  • It was launched using Invoke-Expression, without ever saving an executable file to the disk. That’s why the traditional antivirus software didn’t react. 
  • Curl.exe sent the data out over port 443 to a remote command-and-control server (C2). 
  • All session cookies saved in the Chrome browser were exfiltrated, along with files belonging to several different companies. 
  • The standard Windows firewall allows all outbound traffic without any warning by default — so the attack went unnoticed in real time.

He adds that after a week far less data remained than there could have been. The best course of action, according to the expert, would have been to immediately disconnect from the internet, but not shut down the computer so the RAM wouldn’t get wiped — that’s how most of the picture gets recovered.

Fake CAPTCHA 

According to Ambrazevicius, this was quite a sophisticated attack, involving a hijacked account and a degree of prior preparation. But there are simpler attacks. One of them is fake CAPTCHA — one of the most common ways a ClickFix attack is delivered.

Instead of asking the user to solve an image puzzle, the fake CAPTCHA claims that additional verification steps are required and instructs the user to press a quick sequence of keys. Frequently, that’s Windows Key + R (which opens the Windows native “Run” dialog box), then Ctrl + V (which pastes the hidden malicious payload from the clipboard), and then “Enter” (which executes the command).

“Don’t forget that infostealers don’t just steal passwords — they steal session cookies, the key a server issues after a successful login with 2FA. The criminal loads it into their own browser and opens the account — no password, no code needed. That’s why changing your password after an incident isn’t enough. You need to forcibly terminate all sessions,” Ambrazevicius cautions. 

How to avoid falling victim

  • If someone tells you that you need to update an app because they can’t hear you — that’s a red flag. Contact the person through a different channel. 
  • Be extremely cautious if a website or program unexpectedly asks you to paste text or run commands in PowerShell or Terminal.
  • A familiar name does not equal a familiar person. Accounts get stolen every day. 
  • These days, even if you see or hear someone you know, there’s no guarantee it’s really them — it might be a deepfake. Always exercise caution and agree on a code word that only your family and friends know — and ask for it if things feel suspicious.
  • If you work with sensitive data and suspect such an incident, do not delay — contact a professional. A computer can reveal a great deal, but only until the user unwittingly destroys the evidence.
  • If something like this happens and the sessions and files on your machine are confidential, they must be treated as compromised.

ABOUT NORDPASS

NordPass is a password manager for both business and consumer clients. It’s powered by the latest technology for the utmost security. Developed with affordability, simplicity, and ease of use in mind, NordPass allows users to access passwords securely on desktops, mobile devices, and browsers. All passwords are encrypted on the device, so only the user can access them. NordPass was created by the experts behind NordVPN — the advanced security and privacy app. For more information: nordpass.com.