Tag: email
-
Cisco Warns of Seven ClamAV Flaws, Two With Public PoCs
Cisco warns that seven ClamAV flaws affect Secure Endpoint Connector products, with two having public PoCs that could enable remote DoS attacks. Cisco warned that seven ClamAV vulnerabilities affect its Secure Endpoint Connector on Windows, macOS and Linux. ClamAV is an open-source antivirus engine widely used to scan files and emails for malware. The company…
-
A researcher bought noreply.net. Companies started sending him secrets.
Tags: emailCompanies treat some email domains as digital trash cans, despite the risks. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/08/a-researcher-bought-noreply-net-companies-started-sending-him-secrets/
-
New CSS Bomb Attacks Let Hackers Steal Passwords and Tokens From Webmail Users
Security researcher Gareth Heyes has revealed techniques for webmail attacks that exploit HTML and CSS, the technologies used to format emails, to manipulate user interfaces, leak authentication data, and in some cases, capture passwords. Webmail services need to display HTML controlled by the sender without compromising the security of the mailbox application. To achieve this,…
-
U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data
IEH was breached by a phishing attack that exposed its Microsoft 365 inbox, including emails and potentially export-controlled military data. IEH Corporation is a U.S. defense and aerospace manufacturer based in Brooklyn, New York. The company specializes in high-reliability electrical connectors, particularly hyperboloid connectors used in demanding military and aerospace environments. Its connectors are used…
-
Security Affairs newsletter Round 589 by Pierluigi Paganini INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions Metabase Zero-Day Exploited in the Wild,…
-
Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools
CSS attacks on major webmail services can steal credentials, hijack sessions and manipulate AI tools connected to users’ inboxes. PortSwigger researcher Gareth Heyes demonstrated something that should make every webmail team a little nervous: plain CSS, the styling language that’s supposed to just make text look nice, can be weaponized to steal passwords, hijack sessions, and…
-
Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed
Plus: A judge rules cell tower dumps unconstitutional, water utility hacks spread to a dozen states, a phishing email opens a missile-parts supplier’s inbox, and a ransomware boss gets 16 years. First seen on wired.com Jump to article: www.wired.com/story/flocks-plans-for-rideshare-dashcams-and-coaching-police-revealed/
-
Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All
Two security researchers bought cheap domains”, including noreply.net and deleteduser.com”, and set up email listening services. Hundreds of companies are sending them corporate secrets. First seen on wired.com Jump to article: www.wired.com/story/sensitive-info-goes-into-no-reply-emails-constantly-this-guy-sees-it-all/
-
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
New research shows content inside an email can escape its message boundary and interfere with the webmail interface.Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email.PortSwigger researcher Gareth…
-
Computer maker Framework notifies ‘all customers’ of a data breach
Framework told “all” of its customers that hackers accessed their names, email addresses, phone numbers, and physical addresses in a data breach. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/07/computer-maker-framework-notifies-all-customers-of-a-data-breach/
-
Real emails, hijacked payments: Two H1 2026 attack chains
Gen’s H1 2026 Threat Report examines two separate attack chains. One used compromised business inboxes and browser manipulation in a banking-malware campaign, while the other used clipboard hijacking to redirect cryptocurrency payments. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/real-emails-hijacked-payments-two-h1-2026-attack-chains/
-
MTA Market Shifts: What Domain Owners Should Know
No SPF record found doesn’t mean email stops working, but it removes a layer of sender authorization. Here’s how to assess risk and remediate safely. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/mta-market-shifts-what-domain-owners-should-know/
-
MTA Market Shifts: What Domain Owners Should Know
No SPF record found doesn’t mean email stops working, but it removes a layer of sender authorization. Here’s how to assess risk and remediate safely. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/mta-market-shifts-what-domain-owners-should-know/
-
MTA Market Shifts: What Domain Owners Should Know
No SPF record found doesn’t mean email stops working, but it removes a layer of sender authorization. Here’s how to assess risk and remediate safely. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/mta-market-shifts-what-domain-owners-should-know-2/
-
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
Cybersecurity researchers have called attention to an active “widespread email-driven phishing campaign” that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email.”The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic, First seen on thehackernews.com…
-
Claude in Chrome Exploit Lets Attackers Steal Gmail Codes and Take Over Slack, X, and Claude.ai Accounts
Security researchers have demonstrated an indirect prompt-injection chain affecting Claude in Chrome that can transform a standard request, such as summarizing recent emails, into a cross-account takeover scenario. The research reveals how untrusted content viewed by an AI browser agent can exploit authenticated browser sessions to steal email-delivered verification secrets and compromise accounts on services…
-
Black Hat 2026: Barracuda Details AI-Powered BEC Attack
Barracuda’s Black Hat USA 2026 research shows how AI email assistants can accelerate business email compromise attacks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/black-hat-2026-barracuda-details-ai-powered-bec-attack/
-
Top Email Reputation Services in 2026
Every genuinely free DMARC tool worth knowing, from instant checkers and generators to free-tier monitoring services – what each one actually includes, and where the free limits kick in. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/top-email-reputation-services-in-2026/
-
OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries
Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025. First seen on hackread.com Jump to article: hackread.com/octlurk-silklurk-backdoors-target-6-countries/
-
BlackCloak Expands Impersonation Protection to Executives’ Trusted Circles
BlackCloak is expanding its Impersonation Protection service with a “circle of trust” feature designed to help executives verify communications from the people closest to them. The company announced the capability ahead of Black Hat USA 2026 in Las Vegas. Impersonation Protection lets members authenticate phone calls, video meetings, emails, WhatsApp and Slack messages, texts, and..…
-
Anthropic AI agent faked identities, phished real developers in UK government hacking test
An artificial intelligence agent built by Anthropic independently planted malicious code in a real software project and sent phishing emails to developers during a U.K. government security evaluation, according to Britain’s AI Security Institute. First seen on therecord.media Jump to article: therecord.media/anthropic-ai-hacking-uk
-
Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk
Kali365 is turning a legitimate Microsoft login into a gateway to corporate data.The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft’s real authentication page. Once access and refresh tokens are issued, attackers may retain access to email, documents, and cloud resources, creating a direct path to data exposure, financial…
-
Gmail’s New Feature Warns You Before Revealing You Were BCC’d
Tags: emailGmail now warns BCC recipients before they reply all, helping prevent accidental exposure of their involvement and email address. The post Gmail’s New Feature Warns You Before Revealing You Were BCC’d appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-gmail-bcc-reply-all-warning/
-
Salt Debuts First AWS WAF Managed Ruleset for AI Agent and API Protection
Tags: access, ai, api, attack, ceo, credentials, detection, email, endpoint, exploit, intelligence, marketplace, threat, waf, xssThe WAF gap no one is talking about Your WAF is doing its job. It’s blocking SQLi, XSS, and the usual suspects. But here’s the problem: it wasn’t built for APIs, and it definitely wasn’t built for AI agents. APIs now power nearly every digital experience. And AI agents, the automated systems that access your…
-
INC Ransomware is Calling Victims Pressure Tactics Post SonicWall Zero-Day Exploit
INC Ransomware exploits SonicWall SMA 1000 flaws, using calls and emails to pressure victims during extortion campaigns targeting global organizations. Resecurity disclosed that INC Ransomware has emerged as the dominant threat actor exploiting the recently disclosed SonicWall Secure Mobile Access (SMA) 1000 vulnerabilities. According to the company’s research, the group has accelerated its operations since…
-
Fake Bank of America Phishing Emails Found Delivering Disguised ScreenConnect RAT via UAC Bypass
Researchers at Huntress have identified an active phishing campaign impersonating Bank of America that culminates in the covert installation of a remote monitoring and management (RMM) tool, giving attackers persistent, hard-to-detect access to victims’ Windows machines. The campaign was flagged after a message landed in one of Huntress’s spamtrap accounts on 28 July, sent from…
-
Barracuda Networks Shows How AI Agents Can Compromise Business Email
Barracuda Networks shows how attackers could hijack Microsoft Copilot to access sensitive emails, impersonate executives and execute convincing business email compromise attacks. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/barracuda-networks-shows-how-ai-agents-can-compromise-business-email/
-
Uptime Kuma 2.5.0 waits two weeks before trusting a new npm package
Uptime Kuma checks whether a website, a Docker container, a DNS record, or a Steam game server is still answering, and pushes a message to Telegram, Slack, or email when one … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/04/uptime-kuma-2-5-0-cooldown-npm-updates/

