Advertisement
Autonomous AI Agents Email Security Insights on Perimeter Defences
An autonomous AI agent emailed security researcher Bruce Schneier detailing perimeter defences, anti-bot mechanisms, and invisible prompt injections.
AI Email Summarizers Vulnerable to Hidden HTML Prompts
Attackers can use invisible HTML prompts to manipulate AI email summarizers, generating false information and potential security risks.
Detecting AI-Driven Polymorphic Phishing Attacks
AI-powered phishing attacks leverage personalization and polymorphic evasion, challenging traditional filters. MSPs must focus on post-compromise detection.
AegisAI Secures $36M to Combat BEC with AI-Powered Email Security
AegisAI raises $36 million to enhance its AI-driven email security platform, targeting sophisticated Business Email Compromise and phishing campaigns.
Russian APT Exploits Zimbra Zero-Day to Exfiltrate Mail and 2FA Codes
Russian state-supported actors leveraged a Zimbra Zero-Day to steal 90 days of email history and bypass security by exfiltrating 2FA recovery codes.
Email Account Takeover via 2FA Compromise: Mitigating Identity Theft Risk
An identity theft incident highlights how easily email account takeover via compromised 2FA can lead to broader security breaches. Learn to protect your digital identity.
Advertisement
Apple Patches Hide My Email Bug Exposing Real Addresses in Logs
Apple addresses a privacy flaw in Hide My Email that leaked actual user email addresses in mail logs, undermining the service’s core anonymity features.
Text Salting: Hidden Text Tactics Bypass AI Email Filters
Over 1 million emails are leveraging text salting techniques, embedding hidden characters to bypass AI and LLM-based email security filters, posing a significant…
Finance Executive Email Compromise via Native Windows Tools
A monthslong campaign targeted a global stock exchange executive, leveraging native Windows tools for persistence and unauthorized email monitoring.
New Phishing Campaign Exploits SVG Attachments to Evade Filters
Security researchers report a wave of phishing emails using malicious SVG attachments to deliver scripts and bypass email security gateways. Learn how to defend.
Quishing Evasion: Malicious QR Codes Bypassing Security Filters
A technical analysis of how malicious QR codes (quishing) bypass email security filters and actionable mitigation steps for security operations centers.
Ocean Launches Agentic AI Email Security Platform with $28M Funding
Ocean emerges from stealth with $28M to deploy specialized AI agents that simulate human reasoning to detect sophisticated phishing and BEC threats.
Outlook Junk Folder Bypass: How Attackers Hide Malicious URLs
Discover how attackers bypass Microsoft Outlook's Junk folder link preview protection using HTML manipulation to hide malicious phishing URLs from users.
Amazon SES Phishing Abuse: Evading Security Filters via AWS Infrastructure
Threat actors are increasingly exploiting Amazon Simple Email Service (SES) to bypass email security filters by leveraging high-reputation AWS domains.
AI-Powered Phishing Surges: Defending Against Advanced Attacks
Explore the surge in AI-powered phishing, how threat actors are leveraging it for personalized attacks, and critical defensive strategies for organizations.
Apple ID Alerts Abused for Phishing via Legitimate Servers
Threat actors are exploiting Apple's account notification system to send authentic-looking phishing emails that bypass traditional spam filters and SPF checks.
ZIP Archive Evasion: Detecting Malicious Multi-File Payloads
Analyze how threat actors use ZIP archives containing over 100,000 files to bypass security inspection and overwhelm automated analysis tools.
Bubble Platform Abuse: Credential Phishing Targets Microsoft Accounts
Threat actors are abusing the Bubble no-code platform to host sophisticated phishing campaigns, bypassing traditional detection and targeting Microsoft account…
SVG-Based Phishing: Using Scalable Vector Graphics for Credential Theft
Discover how threat actors leverage SVG files to bypass email filters and execute credential theft through embedded JavaScript and HTML forms.
Abusing .arpa DNS and IPv6 to Bypass Phishing Defenses
Threat actors exploit .arpa domains and IPv6 reverse DNS for phishing evasion, bypassing email security gateways and domain reputation checks.
TOAD Emails: The 'Call This Number' Gateway Bypass Threat
Attackers use Telephone-Oriented Attack Delivery (TOAD) with 'call this number' emails to bypass gateways, relying on social engineering post-call.