< ciso
brief />
Tag Banner

All news with #email security tag

95 articles

Microsoft Outlook to Block .msix and .msixbundle Files

🛡️ Microsoft will add .msix and .msixbundle attachments to the default blocked file types in Outlook on the web and the new Outlook for Windows, starting with a rollout to Exchange Online in early November and GA by mid-November. These package formats are modern Windows installers and bundles used for multiple architectures. Once policies update, users will not be able to send, receive, open, or download these attachments by default, though admins can whitelist them if required. The change is part of ongoing efforts to reduce exploitation of Office and Windows features that attackers abuse.
read more →

Phishing’s new realism: evolving email threats

📧 Modern email phishing now evades traditional telltale signs, using polished language, QR codes, AI-tailored lures and token-theft flows to bypass training and defenses. Attackers exploit live sessions, device hops and legitimate sites to harvest OAuth tokens or trick users into pasting commands, while deepfakes and delayed fraud increase believability. Organizations must pair awareness with verification, layered controls and MDR capabilities to detect and contain these subtler social engineering campaigns.
read more →

Webinar: Prioritizing Google Workspace Security Controls

🛡️ BleepingComputer will host a live webinar on September 23, 2026, titled "Breach autopsy: How fast-growing companies are breached through Google Workspace" with Material Security. Speakers Rajan Kapoor (VP of Security, Material Security) and Rick Fitzgerald (President, Fireside Consulting LLC) will analyze real documented Google Workspace breaches to show which controls matter most. The session focuses on practical prioritization for lean security teams, covering social engineering, malicious OAuth attacks, response actions in the first hours after a breach, and quick improvements ranked by effort and impact.
read more →

Microsoft Defender email security benchmarking updates

📈 This post summarizes Microsoft's latest quarterly email security benchmark covering May–July 2026 and highlights how continuous measurement improves prevention, detection, and adaptation. It reports Defender missed 221 high-severity threats per 1,000 users—55.4% fewer than the next closest SEG vendor—and notes Defender's 92% average post-delivery malicious catch. The report emphasizes evolving threat dynamics driven by AI and outlines Defender investments informed by telemetry and customer feedback.
read more →

Phishing Abuse of Microsoft 365 Direct Send Peaks in US Hours

📧 KnowBe4 researchers observed a large-scale phishing campaign abusing Microsoft 365’s Direct Send feature, with 29,785 confirmed malicious emails sent during July and August 2026. The campaign followed US Eastern business hours, peaking Monday–Tuesday just before noon and again around 2pm EST. Attackers used Direct Send to spoof trusted internal senders and bypass some gateway protections, often including malicious attachments and reply-to addresses directing responses to attackers. The report recommends monitoring the Exchange header "X-MS-Exchange-Organization-AuthAs: Anonymous," enforcing DMARC p=reject, restricting Exchange Online connectors to approved IPs, closing unneeded Direct Send pathways, and enabling DKIM signing.
read more →

Attackers conceal phishing lures with invisible Unicode

🔍 Microsoft researchers revealed a large-scale phishing campaign that used ASCII smuggling by inserting invisible Unicode tag characters into finance-related lure words to evade email filters. The operation peaked at about 2.37 million daily messages in late February and remained active, though diminished, through May 2026. Messages relied on domains promoting funding and loans and were sent via infrastructure tied to the ActiveCampaign platform. Microsoft recommends normalizing or stripping tag-block and other invisible code points before applying keyword or AI-based detection.
read more →

ASCII smuggling used to evade phishing filters

🛡️ Microsoft researchers observed a high-volume phishing campaign that used invisible Unicode tag characters (U+E0000–U+E007F) — a technique popularized in AI prompt-injection research as ASCII smuggling — to split finance lure words and evade email filters. The activity spiked on February 9, 2026, and persisted on weekdays for about three months before declining. Microsoft Defender for Office 365 telemetry shows most messages were caught by layered protections rather than a single Unicode-specific signal. The tactic leverages invisible tag characters to disrupt tokenization and literal keyword matching, making it harder for ML/NLP-based filters to detect phishing lures.
read more →

Amazon SES Adds S/MIME Email Signing Support

🔒 Amazon Simple Email Service (SES) now supports S/MIME signing, enabling recipients to verify that messages are authentic and unaltered. Previously, senders had to pre-sign messages before submitting them to SES, adding operational complexity. Now you can store your signing certificate in AWS Certificate Manager and enable S/MIME for your sender identity so SES signs outbound mail automatically. Recipients without S/MIME-capable clients can still read messages normally, and the feature is available in all Regions where SES operates.
read more →

Hidden HTML can hijack AI email summarizers

🔒 Security researchers demonstrated that an AI email summarizer can be tricked into reading hidden content different from what a user sees. Forcepoint X‑Labs embedded invisible HTML in emails that remained hidden in Outlook but were passed to an LLM-driven summarizer, allowing prompt-injection instructions to alter summaries silently. Their proof-of-concept showed consistent manipulation of invoice dates and omitted names across repeated tests, highlighting risks when untrusted email content is fed to models without guardrails. Forcepoint recommends extracting only visible content, detecting hidden styling, separating headers from body, and validating AI summaries against source material.
read more →

QR code phishing risks and corporate defenses

🛡️ QR codes have become ubiquitous in daily life and are increasingly used in email-based attacks known as "quishing." These attacks encode malicious URLs in QR images to bypass traditional email filters and move victims from managed corporate devices to less-protected personal phones. Threat actors exploit brand impersonation and urgency to harvest credentials, bypass app stores, push fraudulent payments, or capture MFA tokens. Organizations should combine user training, email and mobile security, phishing-resistant MFA, MDM, and incident response planning to reduce risk.
read more →

New CSS attack chains break webmail boundaries

🔒 New research shows HTML and CSS can escape email message boundaries to interfere with webmail UIs across major providers. PortSwigger researcher Gareth Heyes presented proof-of-concept chains at Black Hat USA 2026 targeting Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. The techniques can capture passwords, leak tokens, hijack UI actions, and manipulate AI-connected tools; some PoCs remained public as of August 8.
read more →

Common dangerous file extensions used in email attacks

🛡️ Cybercriminals frequently disguise malicious files as benign documents or archives to trick recipients into executing malware. Kaspersky researchers analyzed malicious email blasts from early 2026 to identify the 15 most abused extensions — from .exe, .dll and .scr to script, web, archive, and Office formats. The report explains how double extensions, hidden extensions, macros, embedded scripts, and password-protected archives are used to evade detection and deliver payloads. It emphasizes keeping software patched, disabling unnecessary macros and scripts, and using advanced security solutions to detect disguised threats.
read more →

Amazon SES simplifies SMTP setup with Mail Manager

📧 Amazon Simple Email Service (SES) now provides a guided console setup for sending email over SMTP using Mail Manager. The new workflow automatically creates and configures required resources and delivers a working SMTP endpoint with downloadable credentials. This lets developers plug SMTP credentials into any application or framework quickly, streamlining transactional and notification email workflows. The feature is available in all AWS Regions where SES is offered.
read more →

First-person identity theft and email risk

🛡️ Harrowing first-person account of identity theft highlights how a single mistake—sharing a two-factor authentication code—enabled a scammer to seize the victim's email. The piece underscores that many online accounts are effectively secured by email access, making email compromise catastrophic. It emphasizes practical lessons about account recovery, 2FA methods, and attacker behaviors.
read more →

Email Agent Hijacking: New Risks in Agentic Email

🛡️ AI agents are processing and acting on emails before humans, creating a new attack surface where malicious content can manipulate agent behavior. This phenomenon, called Email Agent Hijacking (EAH), embeds instructions in email content to influence how AI interprets, prioritizes, or responds. Traditional post-delivery controls are insufficient because agents act immediately; organizations need preventive protections for AI-consumed content and validation for AI-generated outputs.
read more →

Kaspersky introduces AI BEC detection for email

🛡️ Kaspersky explains a new capability to detect AI-generated business email compromise (BEC) messages by identifying both BEC-specific phrases and linguistic patterns typical of machine-generated text. The company notes that cybercriminals increasingly use large language models to craft persuasive phishing and BEC campaigns, and this detection works across eight languages. The feature is integrated into Kaspersky Secure Mail Gateway and available with the KSMS Plus license after the KSMG 3.1 update.
read more →

Critical Zimbra XSS Flaw Targets Classic Web Client

🛡️ Zimbra has released an urgent update to fix a critical stored cross-site scripting (XSS) vulnerability in its Classic Web Client that could permit arbitrary code execution via specially crafted emails. The vendor says the flaw could expose mailbox data, session information, or account settings if exploited, though no CVE has yet been assigned. Zimbra recommends updating to Zimbra Collaboration Suite version 10.1.19 to mitigate the risk.
read more →

How Check Point stopped a student job phishing scam

📧 Check Point Research observed a large phishing campaign that used legitimate school accounts and Google Forms to recruit students into a likely money-mule scheme. The emails passed SPF/DKIM/DMARC and contained no malware or fake login pages, making them appear benign. Check Point Email Security evaluates context, sender behavior, message intent, and hosted-form usage to detect such threats before they reach users.
read more →

Zimbra urges urgent patch for Classic Web Client XSS

🔒 Zimbra released version 10.1.19 to address a critical stored cross-site scripting (XSS) vulnerability in its Classic Web Client that can be triggered via specially crafted emails. The flaw, reported by Google's Threat Analysis Group, allows attackers to execute malicious code when messages are opened and potentially steal session data, account settings, or mailbox contents. Zimbra cautioned customers to upgrade immediately, noting the issue specifically affects Classic Web Client users, while attribution and active exploitation remain under investigation.
read more →

Why attackers target your email inbox aggressively

📧 Email accounts act as hubs for identity verification, password resets and long-term records, making them prime targets for cybercriminals. Attackers use phishing, account takeover, forwarding rules and abused tokens to maintain access, intercept codes and harvest sensitive information. Corporate inbox breaches can lead to data theft, ransomware or expensive fraud, while sophisticated tools like GenAI increase phishing success rates. Regularly review security settings, use MFA or passkeys, and remain vigilant to reduce risk.
read more →