< ciso
brief />
Tag Banner

All news with #email security tag

86 articles

QR code phishing risks and corporate defenses

🛡️ QR codes have become ubiquitous in daily life and are increasingly used in email-based attacks known as "quishing." These attacks encode malicious URLs in QR images to bypass traditional email filters and move victims from managed corporate devices to less-protected personal phones. Threat actors exploit brand impersonation and urgency to harvest credentials, bypass app stores, push fraudulent payments, or capture MFA tokens. Organizations should combine user training, email and mobile security, phishing-resistant MFA, MDM, and incident response planning to reduce risk.
read more →

New CSS attack chains break webmail boundaries

🔒 New research shows HTML and CSS can escape email message boundaries to interfere with webmail UIs across major providers. PortSwigger researcher Gareth Heyes presented proof-of-concept chains at Black Hat USA 2026 targeting Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. The techniques can capture passwords, leak tokens, hijack UI actions, and manipulate AI-connected tools; some PoCs remained public as of August 8.
read more →

Common dangerous file extensions used in email attacks

🛡️ Cybercriminals frequently disguise malicious files as benign documents or archives to trick recipients into executing malware. Kaspersky researchers analyzed malicious email blasts from early 2026 to identify the 15 most abused extensions — from .exe, .dll and .scr to script, web, archive, and Office formats. The report explains how double extensions, hidden extensions, macros, embedded scripts, and password-protected archives are used to evade detection and deliver payloads. It emphasizes keeping software patched, disabling unnecessary macros and scripts, and using advanced security solutions to detect disguised threats.
read more →

Amazon SES simplifies SMTP setup with Mail Manager

📧 Amazon Simple Email Service (SES) now provides a guided console setup for sending email over SMTP using Mail Manager. The new workflow automatically creates and configures required resources and delivers a working SMTP endpoint with downloadable credentials. This lets developers plug SMTP credentials into any application or framework quickly, streamlining transactional and notification email workflows. The feature is available in all AWS Regions where SES is offered.
read more →

First-person identity theft and email risk

🛡️ Harrowing first-person account of identity theft highlights how a single mistake—sharing a two-factor authentication code—enabled a scammer to seize the victim's email. The piece underscores that many online accounts are effectively secured by email access, making email compromise catastrophic. It emphasizes practical lessons about account recovery, 2FA methods, and attacker behaviors.
read more →

Email Agent Hijacking: New Risks in Agentic Email

🛡️ AI agents are processing and acting on emails before humans, creating a new attack surface where malicious content can manipulate agent behavior. This phenomenon, called Email Agent Hijacking (EAH), embeds instructions in email content to influence how AI interprets, prioritizes, or responds. Traditional post-delivery controls are insufficient because agents act immediately; organizations need preventive protections for AI-consumed content and validation for AI-generated outputs.
read more →

Kaspersky introduces AI BEC detection for email

🛡️ Kaspersky explains a new capability to detect AI-generated business email compromise (BEC) messages by identifying both BEC-specific phrases and linguistic patterns typical of machine-generated text. The company notes that cybercriminals increasingly use large language models to craft persuasive phishing and BEC campaigns, and this detection works across eight languages. The feature is integrated into Kaspersky Secure Mail Gateway and available with the KSMS Plus license after the KSMG 3.1 update.
read more →

Critical Zimbra XSS Flaw Targets Classic Web Client

🛡️ Zimbra has released an urgent update to fix a critical stored cross-site scripting (XSS) vulnerability in its Classic Web Client that could permit arbitrary code execution via specially crafted emails. The vendor says the flaw could expose mailbox data, session information, or account settings if exploited, though no CVE has yet been assigned. Zimbra recommends updating to Zimbra Collaboration Suite version 10.1.19 to mitigate the risk.
read more →

How Check Point stopped a student job phishing scam

📧 Check Point Research observed a large phishing campaign that used legitimate school accounts and Google Forms to recruit students into a likely money-mule scheme. The emails passed SPF/DKIM/DMARC and contained no malware or fake login pages, making them appear benign. Check Point Email Security evaluates context, sender behavior, message intent, and hosted-form usage to detect such threats before they reach users.
read more →

Zimbra urges urgent patch for Classic Web Client XSS

🔒 Zimbra released version 10.1.19 to address a critical stored cross-site scripting (XSS) vulnerability in its Classic Web Client that can be triggered via specially crafted emails. The flaw, reported by Google's Threat Analysis Group, allows attackers to execute malicious code when messages are opened and potentially steal session data, account settings, or mailbox contents. Zimbra cautioned customers to upgrade immediately, noting the issue specifically affects Classic Web Client users, while attribution and active exploitation remain under investigation.
read more →

Why attackers target your email inbox aggressively

📧 Email accounts act as hubs for identity verification, password resets and long-term records, making them prime targets for cybercriminals. Attackers use phishing, account takeover, forwarding rules and abused tokens to maintain access, intercept codes and harvest sensitive information. Corporate inbox breaches can lead to data theft, ransomware or expensive fraud, while sophisticated tools like GenAI increase phishing success rates. Regularly review security settings, use MFA or passkeys, and remain vigilant to reduce risk.
read more →

Webinar: Automating email security with behavioral AI

📢 On July 8, 2026, BleepingComputer will present a live webinar titled "Stop chasing alerts: Automating email security with behavioral AI" featuring speakers from Abnormal AI and Novant Health. The session will examine why phishing, BEC, and ATO attacks still generate overwhelming alerts and how behavioral AI can automate detection, investigation, and remediation. Attendees will learn practical techniques to reduce manual workloads, prioritize high-risk incidents, and improve response times across email security operations.
read more →

Growing detection gaps across non-email collaboration platforms

🔍 New research from KnowBe4 finds cybersecurity leaders increasingly lack confidence in detecting threats on non-email channels like Slack and Microsoft Teams. An Infosecurity Europe 2026 survey of 169 professionals reports that 50% of organizations do not have strong visibility across messaging and social platforms, even as 60% say attacks are moving beyond email. While email remains viewed as the riskiest channel, confidence in stopping email attacks (83%) is far higher than for Teams (61%), social media (51%), SMS/WhatsApp (50%) and Slack (40%).
read more →

Microsoft Claims Defender May Replace Other Email Tools

📧 Microsoft’s benchmarking suggests Defender for Office 365 catches most malicious and spam email pre-delivery and removes nearly all threats that reach inboxes, with integrated partners adding negligible improvement. Experts caution against interpreting raw catch rates as proof that one-vendor stacks suffice, noting that small percentages can still represent high-impact incidents and that diverse tools and detection methods remain valuable.
read more →

Cloudflare DMARC Management Generally Available

📣 Cloudflare has made DMARC Management generally available and free for customers, offering a redesigned dashboard to simplify the path to full DMARC enforcement. The tool unifies visibility into SPF, DKIM, DMARC, and BIMI, surfaces sending source IPs, and integrates Cloudflare threat intelligence for investigation. It provides automated record analysis with pass/warning/fail statuses and plain-language recommendations, plus an SPF lookup audit to reveal and resolve the 10-lookup limit. DMARC Management requires Cloudflare DNS and is enabled from Email > DMARC Management in the dashboard.
read more →

Microsoft Defender email security benchmarking insights

📊 Over the past year Microsoft published quarterly, real‑world benchmarking that compares Microsoft Defender against secure email gateway (SEG) and integrated cloud email security (ICES) vendors. The reports show Defender consistently misses fewer high‑severity threats pre‑delivery, while ICES vendors mainly improve promotional and bulk filtering. Defender’s post‑delivery remediation contribution has risen substantially, underscoring its role as a critical backstop.
read more →

Proton’s Balance Between Privacy and Abuse Control

🔒 Proton struggles to block criminals while preserving its core privacy guarantees. COO Raphael Auphan explained that the service cannot access encrypted message contents or geolocate users due to its end-to-end encryption model. Instead, Proton invests in account-level and behavioral defenses, including ML models to detect bot-driven sign-ups and abuse. Lawful takedown requests are handled only after Swiss authorities vet and validate them.
read more →

Microsoft Exchange Online outage delays emails

📧 Microsoft is addressing a widespread service issue impacting the mail flow pipeline for Exchange Online customers in North America and Germany. Users reported SMTP deferral errors and abrupt connection closures, causing significant delays or failures when sending and receiving email. Engineers are investigating incident EX1331830 to identify root causes and restore normal service.
read more →

Amazon SES adds global deliverability insights

📣 Amazon Simple Email Service (SES) introduced enhanced deliverability features that report inbox placement percentages and public email blocklist status. These insights use representative industry samples to show how many messages are routed to spam folders and provide visibility by sending domain and campaign. SES also offers pre-send content testing to estimate inbox placement at major mailbox providers and passive monitoring of blocklist activity. The new capabilities are available in all AWS commercial regions where SES is offered.
read more →

Phishers Use ASCII QR Codes to Evade Scanners Now Widely

🛡️ Attackers have started embedding QR codes as ASCII art in phishing emails to bypass image and link scanners. The lure often impersonates services like DocuSign, instructing victims to scan and enter corporate credentials on mobile devices. Deploying secure email gateways with ASCII-decoding and endpoint protections helps detect and block these campaigns and reduce risk.
read more →