<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Email Security</title><description>Cybersecurity articles tagged #Email Security on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Autonomous AI Agents Email Security Insights on Perimeter Defences</title><link>https://runtimerebel.com/blog/autonomous-ai-agents-email-security-insights-on-perimeter-defences</link><guid isPermaLink="true">https://runtimerebel.com/blog/autonomous-ai-agents-email-security-insights-on-perimeter-defences</guid><description>An autonomous AI agent emailed security researcher Bruce Schneier detailing perimeter defences, anti-bot mechanisms, and invisible prompt injections.</description><pubDate>Wed, 02 Sep 2026 19:09:10 GMT</pubDate><category>Artificial Intelligence</category><category>Prompt Injection</category><category>Bot Management</category><category>Email Security</category></item><item><title>AI Email Summarizers Vulnerable to Hidden HTML Prompts</title><link>https://runtimerebel.com/blog/ai-email-summarizers-vulnerable-to-hidden-html-prompts</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-email-summarizers-vulnerable-to-hidden-html-prompts</guid><description>Attackers can use invisible HTML prompts to manipulate AI email summarizers, generating false information and potential security risks.</description><pubDate>Wed, 26 Aug 2026 00:44:15 GMT</pubDate><category>AI</category><category>Prompt Injection</category><category>Email Security</category><category>Social Engineering</category><category>Hidden HTML</category></item><item><title>Detecting AI-Driven Polymorphic Phishing Attacks</title><link>https://runtimerebel.com/blog/detecting-ai-driven-polymorphic-phishing-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/detecting-ai-driven-polymorphic-phishing-attacks</guid><description>AI-powered phishing attacks leverage personalization and polymorphic evasion, challenging traditional filters. MSPs must focus on post-compromise detection.</description><pubDate>Fri, 21 Aug 2026 08:29:38 GMT</pubDate><category>Spear Phishing</category><category>Email Security</category><category>Threat Detection</category><category>AI Powered Phishing</category><category>Polymorphic Phishing</category></item><item><title>AegisAI Secures $36M to Combat BEC with AI-Powered Email Security</title><link>https://runtimerebel.com/blog/aegisai-secures-36m-to-combat-bec-with-ai-powered-email-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/aegisai-secures-36m-to-combat-bec-with-ai-powered-email-security</guid><description>AegisAI raises $36 million to enhance its AI-driven email security platform, targeting sophisticated Business Email Compromise and phishing campaigns.</description><pubDate>Fri, 24 Jul 2026 13:51:39 GMT</pubDate><category>AegisAI</category><category>Email Security</category><category>BEC</category><category>AI Security</category><category>Cloud Security</category></item><item><title>Russian APT Exploits Zimbra Zero-Day to Exfiltrate Mail and 2FA Codes</title><link>https://runtimerebel.com/blog/russian-apt-exploits-zimbra-zero-day-to-exfiltrate-mail-and-2fa-codes</link><guid isPermaLink="true">https://runtimerebel.com/blog/russian-apt-exploits-zimbra-zero-day-to-exfiltrate-mail-and-2fa-codes</guid><description>Russian state-supported actors leveraged a Zimbra Zero-Day to steal 90 days of email history and bypass security by exfiltrating 2FA recovery codes.</description><pubDate>Thu, 23 Jul 2026 21:06:08 GMT</pubDate><category>Zimbra</category><category>Russian Espionage</category><category>APT28</category><category>Zero-Day</category><category>Email Security</category></item><item><title>Email Account Takeover via 2FA Compromise: Mitigating Identity Theft Risk</title><link>https://runtimerebel.com/blog/email-account-takeover-via-2fa-compromise-mitigating-identity-theft-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/email-account-takeover-via-2fa-compromise-mitigating-identity-theft-risk</guid><description>An identity theft incident highlights how easily email account takeover via compromised 2FA can lead to broader security breaches. Learn to protect your digital identity.</description><pubDate>Wed, 22 Jul 2026 17:24:17 GMT</pubDate><category>Identity Theft</category><category>Account Takeover</category><category>2FA Bypass</category><category>Email Security</category><category>Phishing</category><category>Social Engineering</category></item><item><title>Apple Patches Hide My Email Bug Exposing Real Addresses in Logs</title><link>https://runtimerebel.com/blog/apple-patches-hide-my-email-bug-exposing-real-addresses-in-logs</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-patches-hide-my-email-bug-exposing-real-addresses-in-logs</guid><description>Apple addresses a privacy flaw in Hide My Email that leaked actual user email addresses in mail logs, undermining the service’s core anonymity features.</description><pubDate>Tue, 21 Jul 2026 21:11:31 GMT</pubDate><category>Apple</category><category>Hide My Email</category><category>Privacy Vulnerability</category><category>Email Security</category><category>Data Exposure</category></item><item><title>Text Salting: Hidden Text Tactics Bypass AI Email Filters</title><link>https://runtimerebel.com/blog/text-salting-hidden-text-tactics-bypass-ai-email-filters</link><guid isPermaLink="true">https://runtimerebel.com/blog/text-salting-hidden-text-tactics-bypass-ai-email-filters</guid><description>Over 1 million emails are leveraging text salting techniques, embedding hidden characters to bypass AI and LLM-based email security filters, posing a significant…</description><pubDate>Thu, 16 Jul 2026 21:02:58 GMT</pubDate><category>Text Salting</category><category>Phishing</category><category>AI Security</category><category>Email Security</category><category>LLMs</category><category>Obfuscation</category></item><item><title>Finance Executive Email Compromise via Native Windows Tools</title><link>https://runtimerebel.com/blog/finance-executive-email-compromise-via-native-windows-tools</link><guid isPermaLink="true">https://runtimerebel.com/blog/finance-executive-email-compromise-via-native-windows-tools</guid><description>A monthslong campaign targeted a global stock exchange executive, leveraging native Windows tools for persistence and unauthorized email monitoring.</description><pubDate>Wed, 03 Jun 2026 13:50:15 GMT</pubDate><category>Financial Sector</category><category>Email Security</category><category>Living-off-the-Land</category><category>M365 Security</category></item><item><title>New Phishing Campaign Exploits SVG Attachments to Evade Filters</title><link>https://runtimerebel.com/blog/new-phishing-campaign-exploits-svg-attachments-to-evade-filters</link><guid isPermaLink="true">https://runtimerebel.com/blog/new-phishing-campaign-exploits-svg-attachments-to-evade-filters</guid><description>Security researchers report a wave of phishing emails using malicious SVG attachments to deliver scripts and bypass email security gateways. Learn how to defend.</description><pubDate>Tue, 02 Jun 2026 09:35:03 GMT</pubDate><category>Phishing</category><category>SVG</category><category>Malware Delivery</category><category>Social Engineering</category><category>Email Security</category></item><item><title>Quishing Evasion: Malicious QR Codes Bypassing Security Filters</title><link>https://runtimerebel.com/blog/quishing-evasion-malicious-qr-codes-bypassing-security-filters</link><guid isPermaLink="true">https://runtimerebel.com/blog/quishing-evasion-malicious-qr-codes-bypassing-security-filters</guid><description>A technical analysis of how malicious QR codes (quishing) bypass email security filters and actionable mitigation steps for security operations centers.</description><pubDate>Mon, 01 Jun 2026 05:43:53 GMT</pubDate><category>Quishing</category><category>Phishing</category><category>Email Security</category><category>Social Engineering</category><category>Evasion Techniques</category></item><item><title>Ocean Launches Agentic AI Email Security Platform with $28M Funding</title><link>https://runtimerebel.com/blog/ocean-launches-agentic-ai-email-security-platform-with-28m-funding</link><guid isPermaLink="true">https://runtimerebel.com/blog/ocean-launches-agentic-ai-email-security-platform-with-28m-funding</guid><description>Ocean emerges from stealth with $28M to deploy specialized AI agents that simulate human reasoning to detect sophisticated phishing and BEC threats.</description><pubDate>Thu, 21 May 2026 13:21:56 GMT</pubDate><category>Email Security</category><category>Agentic AI</category><category>Phishing</category><category>Business Email Compromise</category><category>Ocean Security</category></item><item><title>Outlook Junk Folder Bypass: How Attackers Hide Malicious URLs</title><link>https://runtimerebel.com/blog/outlook-junk-folder-bypass-how-attackers-hide-malicious-urls</link><guid isPermaLink="true">https://runtimerebel.com/blog/outlook-junk-folder-bypass-how-attackers-hide-malicious-urls</guid><description>Discover how attackers bypass Microsoft Outlook&apos;s Junk folder link preview protection using HTML manipulation to hide malicious phishing URLs from users.</description><pubDate>Thu, 14 May 2026 09:05:32 GMT</pubDate><category>Microsoft Outlook</category><category>Phishing Defense</category><category>Email Security</category><category>Link Preview Bypass</category><category>Html Manipulation</category></item><item><title>Amazon SES Phishing Abuse: Evading Security Filters via AWS Infrastructure</title><link>https://runtimerebel.com/blog/amazon-ses-phishing-abuse-evading-security-filters-via-aws-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/amazon-ses-phishing-abuse-evading-security-filters-via-aws-infrastructure</guid><description>Threat actors are increasingly exploiting Amazon Simple Email Service (SES) to bypass email security filters by leveraging high-reputation AWS domains.</description><pubDate>Mon, 04 May 2026 20:35:07 GMT</pubDate><category>Amazon SES</category><category>Phishing</category><category>AWS Security</category><category>Email Security</category><category>Credential Theft</category></item><item><title>AI-Powered Phishing Surges: Defending Against Advanced Attacks</title><link>https://runtimerebel.com/blog/ai-powered-phishing-surges-defending-against-advanced-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-powered-phishing-surges-defending-against-advanced-attacks</guid><description>Explore the surge in AI-powered phishing, how threat actors are leveraging it for personalized attacks, and critical defensive strategies for organizations.</description><pubDate>Fri, 24 Apr 2026 16:30:03 GMT</pubDate><category>AI Phishing</category><category>Social Engineering</category><category>Email Security</category><category>Cybercrime</category><category>Threat Intelligence</category></item><item><title>Apple ID Alerts Abused for Phishing via Legitimate Servers</title><link>https://runtimerebel.com/blog/apple-id-alerts-abused-for-phishing-via-legitimate-servers</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-id-alerts-abused-for-phishing-via-legitimate-servers</guid><description>Threat actors are exploiting Apple&apos;s account notification system to send authentic-looking phishing emails that bypass traditional spam filters and SPF checks.</description><pubDate>Sun, 19 Apr 2026 16:16:02 GMT</pubDate><category>Apple Id</category><category>Phishing</category><category>Social Engineering</category><category>Email Security</category><category>Spam Bypass</category></item><item><title>ZIP Archive Evasion: Detecting Malicious Multi-File Payloads</title><link>https://runtimerebel.com/blog/zip-archive-evasion-detecting-malicious-multi-file-payloads</link><guid isPermaLink="true">https://runtimerebel.com/blog/zip-archive-evasion-detecting-malicious-multi-file-payloads</guid><description>Analyze how threat actors use ZIP archives containing over 100,000 files to bypass security inspection and overwhelm automated analysis tools.</description><pubDate>Fri, 27 Mar 2026 04:52:03 GMT</pubDate><category>Evasion Techniques</category><category>Malware Delivery</category><category>ZIP Archives</category><category>Email Security</category></item><item><title>Bubble Platform Abuse: Credential Phishing Targets Microsoft Accounts</title><link>https://runtimerebel.com/blog/bubble-platform-abuse-credential-phishing-targets-microsoft-accounts</link><guid isPermaLink="true">https://runtimerebel.com/blog/bubble-platform-abuse-credential-phishing-targets-microsoft-accounts</guid><description>Threat actors are abusing the Bubble no-code platform to host sophisticated phishing campaigns, bypassing traditional detection and targeting Microsoft account…</description><pubDate>Wed, 25 Mar 2026 20:16:59 GMT</pubDate><category>Phishing</category><category>Credential Theft</category><category>Microsoft Accounts</category><category>Bubble Platform</category><category>No Code Security</category><category>Email Security</category></item><item><title>SVG-Based Phishing: Using Scalable Vector Graphics for Credential Theft</title><link>https://runtimerebel.com/blog/svg-based-phishing-using-scalable-vector-graphics-for-credential-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/svg-based-phishing-using-scalable-vector-graphics-for-credential-theft</guid><description>Discover how threat actors leverage SVG files to bypass email filters and execute credential theft through embedded JavaScript and HTML forms.</description><pubDate>Wed, 25 Mar 2026 04:43:26 GMT</pubDate><category>SVG Phishing</category><category>Credential Theft</category><category>Email Security</category><category>Obfuscation</category></item><item><title>Abusing .arpa DNS and IPv6 to Bypass Phishing Defenses</title><link>https://runtimerebel.com/blog/abusing-arpa-dns-and-ipv6-to-bypass-phishing-defenses</link><guid isPermaLink="true">https://runtimerebel.com/blog/abusing-arpa-dns-and-ipv6-to-bypass-phishing-defenses</guid><description>Threat actors exploit .arpa domains and IPv6 reverse DNS for phishing evasion, bypassing email security gateways and domain reputation checks.</description><pubDate>Sun, 08 Mar 2026 16:22:28 GMT</pubDate><category>Phishing</category><category>Arpa</category><category>IPv6</category><category>DNS</category><category>Email Security</category><category>Evasion</category></item><item><title>TOAD Emails: The &apos;Call This Number&apos; Gateway Bypass Threat</title><link>https://runtimerebel.com/blog/toad-emails-the-call-this-number-gateway-bypass-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/toad-emails-the-call-this-number-gateway-bypass-threat</guid><description>Attackers use Telephone-Oriented Attack Delivery (TOAD) with &apos;call this number&apos; emails to bypass gateways, relying on social engineering post-call.</description><pubDate>Wed, 25 Feb 2026 16:34:30 GMT</pubDate><category>TOAD</category><category>Telephone Oriented Attack Delivery</category><category>Social Engineering</category><category>Email Security</category><category>Phishing</category></item></channel></rss>