Tag: email
-
Japanese media group Nikkei discloses intrusions targeting employees and users
The Japanese media giant Nikkei disclosed a cyber incident involving an employee email account that may have compromised journalistic sources. First seen on therecord.media Jump to article: therecord.media/nikkei-cyberattack-japan-data
-
New Stealthy Linux Backdoors Target Telecoms, Masquerade as Email Traffic
Rapid7 has uncovered new BPFDoor, BPF Rekoobe and AVERAT malware variants targeting telecom and network-edge appliances in South Korea and Taiwan First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/smtp-linux-backdoors-network-edge/
-
Japanese media group Nikkei discloses cyberattack targeting journalistic sources
The Japanese media giant Nikkei disclosed a cyber incident involving an employee email account that may have compromised journalistic sources. First seen on therecord.media Jump to article: therecord.media/nikkei-cyberattack-japan-data
-
Nikkei Cyberattack Hijacks Employee Accounts, Sends 9,000 Spoofed Emails
Nihon Keizai Shimbun disclosed on October 4 that a Nikkei cyberattack had compromised employees’ Microsoft 365 business software accounts. Attackers then used those accounts to send roughly 9,000 spoofed emails to people inside and outside the company. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/nikkei-cyberattack/
-
Security Affairs newsletter Round 598 by Pierluigi Paganini INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Fake Zoom installer hides macOS backdoor CloudSyncD CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed Antino Backdoor Lets…
-
OpenAI’s Medicare attack has exposed Australia’s ‘tech debt’. Fixing it could bring a big bill for taxpayers
Home affairs department orders all federal government agencies to conduct review of ‘legacy technology’ amid fallout from AI agent hacks <ul><li>Get our <a href=”https://www.theguardian.com/email-newsletters?CMP=cvau_sfl”>breaking news email, <a href=”https://app.adjust.com/w4u7jx3″>free app or <a href=”https://www.theguardian.com/australia-news/series/full-story?CMP=cvau_sfl”>daily news podcast</li></ul>The Australian government faces significant “tech debt” that could bring a big bill for taxpayers after the <a href=”https://www.theguardian.com/technology/2026/sep/24/openai-agent-hacked-medicare-australia-what-we-know-so-far-ntwnfb”>OpenAI Medicare breach, as…
-
Malicious Email Could Hijack AI Agent and Access Connected Accounts
Security researchers have uncovered a now-fixed vulnerability in agentic AI platform Manus that could have allowed attackers to hijack an AI agent through a single malicious email and potentially access a user’s connected accounts. Researchers at Salt Labs, the research arm of Salt Security, found that Manus could interpret malicious instructions embedded within an incoming…
-
Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)
Fortinet is warning customers that attackers are exploiting a zero-day vulnerability (CVE-2026-104286) in FortiMail, its email security gateway. Fortinet says the flaw has … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/10/02/fortinet-fortimail-vulnerability-cve-2026-104286/
-
Fortinet FortiMail Path Traversal Flaw Actively Exploited to Compromise Servers
Fortinet has disclosed a critical vulnerability in FortiMail that attackers are actively exploiting to compromise vulnerable email security appliances. This flaw, tracked as CVE-2026-104286, has a CVSS v3.1 score of 9.8. It enables unauthenticated attackers to write arbitrary files to the underlying system via specially crafted HTTP or HTTPS requests. Fortinet FortiMail Path Traversal Flaw…
-
Kiteworks patches max severity code injection vulnerability
Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway (EPG) security solution. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/kiteworks-patches-max-severity-email-protection-gateway-code-injection-vulnerability/
-
Attackers have been exploiting critical Zimbra flaw to steal emails
A simple email gives the attackers the ability to remotely inject OS commands. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/09/attackers-have-been-exploiting-critical-zimbra-flaw-to-steal-emails/
-
Former US Air Force members sent to prison over BEC attacks
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/former-us-air-force-members-sent-to-prison-over-bec-attacks/
-
Hackers Use Hijacked University Emails to Scam Students, Pose as FBI Agent
Students, job seekers and university staff, watch out for fake job offers sent from legitimate university email accounts. First seen on hackread.com Jump to article: hackread.com/hackers-hijacked-university-emails-scam-students-fake-jobs/
-
Russian pizza chain with 1,500 locations confirms cyberattack following hacker claims
According to Dodo Pizza, the potentially compromised information included customers’ names, addresses, email addresses, phone numbers, dates of birth and order details. First seen on therecord.media Jump to article: therecord.media/russian-pizza-chain-dodo-confirms-data-breach
-
Russian pizza chain with 1,500 locations confirms cyberattack following hacker claims
According to Dodo Pizza, the potentially compromised information included customers’ names, addresses, email addresses, phone numbers, dates of birth and order details. First seen on therecord.media Jump to article: therecord.media/russian-pizza-chain-dodo-confirms-data-breach
-
Russian pizza chain with 1,500 locations confirms cyberattack following hacker claims
According to Dodo Pizza, the potentially compromised information included customers’ names, addresses, email addresses, phone numbers, dates of birth and order details. First seen on therecord.media Jump to article: therecord.media/russian-pizza-chain-dodo-confirms-data-breach
-
Proton brings Microsoft 365 to Easy Switch for Business as security leaders weigh US ‘kill switch’ risk
Proton has extended Easy Switch for Business, its guided migration tool, to Microsoft 365. Organisations can now move email, calendars and contacts from Outlook or Google Workspace to Proton’s end-to-end encrypted platform without taking their teams offline. The tool first launched for Google Workspace in June. Adding Microsoft 365 opens it up to the platform…
-
Fake Email Thread Tricks AI Summarizer Without Hidden Text
Forcepoint X-Labs has published new research showing that indirect prompt injection against AI email summarizers can work without… First seen on hackread.com Jump to article: hackread.com/fake-email-thread-tricks-ai-summarizer-hidden-text/
-
OpenAI is preparing “o,” an always-on ChatGPT assistant that could handle email
OpenAI is testing a new always-on assistant called “o”, and references to the unannounced feature briefly showed up on the company’s website. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/artificial-intelligence/openai-is-preparing-o-an-always-on-chatgpt-assistant-that-could-handle-email/
-
Security Affairs newsletter Round 597 by Pierluigi Paganini INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. OpenAI Agents Accessed US Government Websites Without Authorization Exploit.in Database Reveals the Roots of Today’s Ransomware Ecosystem…
-
Exposed GitLab project email addresses let attackers push code
Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/exposed-gitlab-project-email-addresses-let-attackers-push-code/
-
Roundcube Webmail Flaw Lets Attackers Trigger SQL Injection Without Authentication
A highly severe vulnerability in Roundcube Webmail is being actively exploited, posing risks to unpatched email servers through unauthenticated SQL injection attacks. This vulnerability, tracked as CVE-2026-48842, affects Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. On September 21, the Canadian Center for Cyber Security updated advisory AV26-503, warning that reports from the…
-
GitLab Email Token Lets Attackers Push Code to Main and Execute CI/CD Jobs
A long-lived GitLab incoming email token embedded in project email addresses for the >>Email work item<< feature can be exploited to push attacker-controlled code, create merge requests, and trigger CI/CD pipelines using the permissions of the token owner. This issue can also bypass GitLab's IP restrictions, as incoming email is explicitly excluded from those controls.…
-
Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud
The popular phishing-as-a-service platform used AI throughout the attack chain, allowing cybercriminals to steal tokens for account takeover and business email compromise. First seen on cyberscoop.com Jump to article: cyberscoop.com/microsoft-eviltokens-cybercrime-service-takedown/
-
Hackers Abuse Microsoft Teams to Pose as IT Support and Steal Employee Passwords
Threat actors are increasingly abusing Microsoft Teams’ external chat capabilities to impersonate corporate IT help desks. They trick employees into installing malware, granting remote access, and stealing Windows credentials. These attacks exploit a simple vulnerability: employees tend to distrust suspicious emails but often do not apply the same caution to collaboration platforms like Teams. Attackers…
-
Bumrungrad turns to AI agents to clear patient email backlog
Bumrungrad International Hospital is using Salesforce’s Agentforce to summarise and route patient correspondence, with automated appointment booking and voice agents on the cards First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650856/Bumrungrad-turns-to-AI-agents-to-clear-patient-email-backlog
-
Aktiv ausgenutzte SQL Injection – Root-Zugriff auf Cisco Secure Email Gateway per E-Mail
First seen on security-insider.de Jump to article: www.security-insider.de/cisco-secure-email-gateway-sql-injection-root-rechte-a-9e285fdd581f2d5e9a7203bf213d3f82/
-
Week in review: Cisco patches exploited email gateway 0-day, Revolut breach
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: What we know about the Revolut data breach so far Someone impersonating a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/20/week-in-review-cisco-patches-exploited-email-gateway-0-day-revolut-breach/
-
Reαd carefully: how to spot and avoid a homoglyph attack
Scam emails are increasingly using psychological tricks, such as using near-identical URLs like miÑrosoft.comYou’ve read the email carefully and it looks legitimate. The link it asks you to click on has none of the usual red flags: there are no weird numbers or extra parts to the URL. You feel safe to proceed.But if you…

