Tag: email
-
Russia-backed threat actor targets Western organizations in phishing campaign
The threat actor exploited a zero-day flaw in Zimbra to exfiltrate months of emails and other sensitive information. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/russia-threat-actor-western-organizations-Zimbra-phishing/826029/
-
TA488 and TA458 Steal Government Email Using Half-Click Webmail Exploits
At a Glance Actor or group TA488 (Void Blizzard, Laundry Bear) and TA458 (Operation RoundPress), both Russia-aligned Activity First seen on securityonline.info Jump to article: securityonline.info/half-click-exploits-webmail/
-
Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts
Google on Thursday announced a new way for users to sign-in to their accounts by letting them take a selfie video.The selfie for sign-in, per the tech giant, is another option on top of existing recovery methods to log in to an account, including an email address or a phone number. The idea is to…
-
Microsoft Adds Prompt Injection Protection to Defender for Office 365
Microsoft has introduced prompt injection protection in Defender for Office 365, representing a significant advancement in securing enterprise email environments against emerging AI-targeted threats. As organizations increasingly adopt AI assistants like Microsoft 365 Copilot to summarize, triage, and respond to emails, attackers are shifting their tactics from traditional phishing methods to manipulating AI systems directly.…
-
Apple Fixes Hide My Email Vulnerability That Exposed Users’ Real Email Addresses
Apple has addressed a year-old vulnerability in its >>Hide My Email<< privacy feature, which could expose users' real email addresses. This incident has already led to a class action lawsuit and increased scrutiny of Apple's privacy claims. Hide My Email, part of the paid iCloud+ subscription, allows users to generate random alias addresses that forward…
-
Apple Faces Lawsuit Over Hide My Email Privacy Vulnerability
Apple is facing a proposed class-action lawsuit after Anthony Alvarez alleged that the company’s Hide My Email feature failed to protect users’ real email addresses as advertised. The complaint, filed in the U.S. District Court for the Northern District of California, claims Apple promoted Hide My Email as a privacy safeguard while continuing to charge customers for…
-
Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs
Apple has moved to address a security flaw in its Hide My Email service that enabled users’ real email addresses to be unmasked, effectively undermining the feature’s privacy guarantees.404 Media reported Tuesday that a fix for the issue was deployed by Apple on July 3, 2026, after more than a year, when it was disclosed…
-
Ransomware victims fail to fix flaws that exposed them
Many organizations still aren’t securing their email or patching vulnerabilities after recovering from attacks, a new report found. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ransomware-lingering-weaknesses-black-kite/825791/
-
Hackers Use Cruciferra Crypter to Disable EDR and Deploy XWorm, Remcos, and AsyncRAT
Hackers are abusing the Cruciferra crypter-as-a-service to systematically turn off endpoint detection and response (EDR) tools and stealthily deploy XWorm, Remcos, AsyncRAT, and other commodity malware in email-driven campaigns targeting multiple sectors worldwide. By combining BYOVD-based driver abuse, indirect syscalls and a polymorphic encryption engine with more than 90 mix-and-match crypto routines, Cruciferra has rapidly…
-
Over 1 million malicious emails found using text salting to fool AI scanners
First seen on scworld.com Jump to article: www.scworld.com/news/over-1-million-malicious-emails-found-using-text-salting-to-fool-ai-scanners
-
Security Affairs newsletter Round 586 by Pierluigi Paganini INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. OpenSSL Fixes HollowByte Memory Exhaustion Bug Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s Network…
-
Million Email Phishing Campaign Uses Text Salting
Barracuda researchers identified more than one million phishing emails using text salting to manipulate AI-powered email security. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/million-email-phishing-campaign-uses-text-salting/
-
Apple Sued Over Hide My Email Privacy Claims
Apple faces a proposed class action alleging a Hide My Email flaw could expose users’ real addresses despite the company’s privacy claims. The post Apple Sued Over Hide My Email Privacy Claims appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-apple-hide-my-email-privacy-lawsuit/
-
“TTF Trap” Phishing Emails Use Fake Font Files to Deliver Windows Malware
An email that appears to contain a shipping document, payment request, or business proposal can infect a Windows… First seen on hackread.com Jump to article: hackread.com/ttf-trap-phishing-fake-font-files-windows-malware/
-
Hackers Hide Lua Loaders in Fake TTF Files to Deploy Remcos, XWorm, and Agent Tesla
Hackers are increasingly abusing trusted file formats and lightweight scripting environments to evade detection, with a newly observed campaign leveraging Lua-based loaders. Disguised as TrueType (.ttf) font files to deploy commodity malware, including Remcos RAT, Agent Tesla, XWorm, and Snake Keylogger variants. The campaign impersonates legitimate businesses and brands in email lures, often using payment-themed…
-
1M+ Emails Use Hidden Text to Dupe AI Security Filters
Artificial intelligence and LLMs can be surprisingly ineffective against text salting, allowing phishing emails to slide right into your inbox. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/1m-emails-hidden-text-dupe-ai-security-filters
-
Russian celebrity journalist Ksenia Sobchak says hackers accessed Telegram channels via email breach
Following the breach of several of her Telegram channels, controversial Russian journalist Ksenia Sobchak claimed published screenshots of her correspondence with political figures were fake. First seen on therecord.media Jump to article: therecord.media/ksenia-sobchak-russian-hackers-leak
-
New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email
Give an AI assistant a memory and access to your inbox, and you hand an attacker a way to rewrite what it thinks it knows about you. A single email can trick that agent into saving a false “fact” about the user, hide the change, and quietly steer its answers in later sessions.When it works,…
-
Turning the Tables on Email Scammers With ‘ScamBuster’
An open source, AI-driven system adopts victim personas to engage with phishing attackers, allowing organizations and law enforcement to gather relevant data on cybercriminal operations. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/turning-tables-email-scammers-scambuster
-
Operation Capsule Vault Uses Malicious ISO Files and Process Injection to Deliver RokRAT
Operation Capsule Vault began with spear-phishing emails sent on June 22, 2026, posing as notices distributing materials from a legitimate academic event. The lures referenced the “Why Wonsan-Kalma Tourism Now?” conference, held at Seoul COEX on June 12, and incorporated publicly available event details, including its subject matter and host organizations. By reusing real-world conference…
-
A Majority of European Lawmakers Voted Against Letting Big Tech Read Our Messages. They’re Going to Anyway
Tags: emailCompanies will once again be allowed to scan citizens’ personal texts, emails, and social media messages via the “Chat Control” bill to find child abuse material online. First seen on wired.com Jump to article: www.wired.com/story/a-majority-of-european-lawmakers-voted-against-letting-big-tech-read-our-messages-theyre-going-to-anyway/
-
Invited to a >>job interview<< with Netflix or OpenAI? Beware! Your Google password could be at risk
Have you received an email from a recruiter at Adobe, Netflix, or OpenAI offering you an exciting new marketing role? Well, before you start brushing up your interview technique, take a closer look at who is really behind it. First seen on bitdefender.com Jump to article: www.bitdefender.com/en-us/blog/hotforsecurity/invited-job-interview-netflix-openai-beware-google-password
-
A Majority of European Lawmakers Voted Against Letting Big Tech Read Our Messages. They’re Going to Anyway.
Tags: emailCompanies will once again be allowed to scan citizens’ personal texts, emails, and social media messages via the “chat control” bill to find child abuse material online. First seen on wired.com Jump to article: www.wired.com/story/a-majority-of-european-lawmakers-voted-against-letting-big-tech-read-our-messages-theyre-going-to-anyway/
-
Microsoft to retire the OWA Light client in Exchange Server
Microsoft has announced plans to disable Outlook Web Access (OWA) Light, the lightweight version of the Outlook Web App email client, in a future Exchange Server update. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-announces-owa-light-retirement-in-exchange-server/
-
SNOW Malware Ecosystem Uses Teams Phishing, WebSocket Tunnels, and Browser Extensions
Threat actors are increasingly chaining classic phishing with collaboration platforms and covert tunneling to create highly believable intrusion paths. A recent multi-stage campaign attributed to UNC6692 exposes how adversaries combine email bombardment, Microsoft Teams impersonation, malicious browser extensions, WebSocket tunnels, and Python backdoors into a single, resilient ecosystem known as SNOW. The campaign began with…
-
SNOW Malware Ecosystem Uses Teams Phishing, WebSocket Tunnels, and Browser Extensions
Threat actors are increasingly chaining classic phishing with collaboration platforms and covert tunneling to create highly believable intrusion paths. A recent multi-stage campaign attributed to UNC6692 exposes how adversaries combine email bombardment, Microsoft Teams impersonation, malicious browser extensions, WebSocket tunnels, and Python backdoors into a single, resilient ecosystem known as SNOW. The campaign began with…
-
Claude AI Prompt Injection Attack Turns Chatbot Into Stealthy C2 Agent to Achieve Remote Code Execution
Claude Desktop’s synced Personal Preferences feature can be exploited as a covert prompt-injection vector, transforming the AI assistant into a de facto command-and-control (C2) agent. This method allows for remote code execution on a compromised user workstation without the need for phishing emails or traditional malware delivery. In this attack chain, the initial access is…
-
New Ghost Phishing Wave Is Breaking Traditional Email Security
A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser.For security leaders, the risk is clear: traditional URL checks may miss the attack while Microsoft 365…
-
Telco giant KDDI says data breach affects over 12 million people
Japanese telecommunications giant KDDI says that millions of people had their email addresses and passwords exposed after attackers breached an email platform used by five internet service providers (ISPs) in the country. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/japanese-telecom-giant-kddi-says-data-breach-affects-12-million-people/

