Product updates: 2026.08-09
Improved threat reporting add-ins
You'll find this in the Outlook and Gmail reporting add-ins, with the reported details appearing under Threats.
The report add-ins have a new design. The Gmail add-in can now report an email as spam, not just phishing.
When reporting, employees can flag whether they clicked a link or opened an attachment, and add an optional comment for the security team. This information now appears on the threat's report page, alongside whether the employee interacted with the email and their note.
We also fixed a number of smaller bugs in the add-ins.
Microsoft Teams notifications
You'll find this under Integrations > Notifications.
Employees can now receive Moxso training notifications directly in Microsoft Teams, instead of only by email. This covers onboarding reminders, mandatory course, video, and policy assignments, training reminders, remedial training messages, new breach notifications, reported-threat status updates, and HRI interventions. System notifications, password resets, and phishing simulations are still sent by email only, and enabling Teams doesn't turn off email notifications; it's an additional channel.
Setup has two parts: an admin installs the Moxso notification app through the Microsoft Teams Admin Center, then connects and enables it in Moxso. You'll need a Teams or Global administrator account, and you can scope the app to specific users or groups instead of your whole organization. After enabling, Microsoft installs the app for each user overnight, so employees typically start receiving notifications the next day.
Simulation campaign improvements
Staggered delivery for one-off simulations
You'll find this under Simulations, when creating a simulation.
Launching a one-off simulation used to send it to every employee in the audience within a few minutes. You can now stagger delivery across 1 to 7 days, so employees receive it at different times instead of all at once.
This is off by default, so unless you choose a number of days, simulations send the way they always have. It works for both email and text message simulations, and you can stop a campaign at any time, which cancels any simulations still pending.
Delete draft simulations
Draft campaigns that have never been launched can now also be deleted.
Threat grouping
You'll find this under Threats, with settings under Settings > Threats.
Similar threats are now grouped together automatically, so the threats overview shows one entry per group instead of every duplicate, and you can update the status of a whole group at once. You can also turn on automatic status assignment for new reports in a group. See our Threat Management guide for the full details.
Repeated behavior escalation in HRI
You'll find this under Human risk intelligence > Settings, under Intervention signal groups. Triggered interventions appear under Human risk intelligence > Interventions.
HRI can now automatically respond when an employee repeats certain risky behaviors, instead of only reacting to single events.
Choose which signal groups to monitor, such as phishing interactions, critical phishing interactions (submitting credentials, opening an attachment, or replying), breach exposure, simulation non-reporting, or training inactivity, and set an activation threshold for each, such as 2 occurrences within 90 days.
When a signal group's threshold is met, HRI can automatically assign corrective training, or notify the employee, their manager, or workspace admins. You can also set a maximum number of interventions per employee and a cooldown period between them.
Triggered interventions appear under Interventions, where you can filter by signal type and see what action was taken for each employee. Two new signals, training inactivity and simulation non-reporting, are also available to monitor.
Enhanced manager reports
You'll find this under Export, when scheduling a Manager Report.
Manager reports now give a clearer view of team security behavior over time. Each report includes a team summary compared against company averages, six-month trends for resilience score, click rate, and report rate, training and simulation activity, missed deadlines, and a list of employees at risk, plus an individual report for each employee on the team.
If Human Risk Intelligence is enabled, the report also includes HRI signals: sentiment and severity breakdowns, the most dangerous signals for the period, and recent interventions.
Reports are fully localized in each recipient's profile language, and you can now choose a Last 12 months period in addition to the existing options. Turn on Enable roll up reporting to include employees further down the hierarchy, not just direct reports.
A few fixes and changes came with this update:
- Click rate and report rate are now calculated as a 12-month rolling average instead of month by month, which flattens the curve and makes the numbers more reliable and less spiky.
- Inactive and anonymous employees no longer appear in reports.
- All missed deadlines are now included, instead of a partial list.