email security

Roundcube Webmail Vulnerability in Attackers’ Crosshairs

Roundcube Webmail Vulnerability in Attackers’ Crosshairs 2026-09-25 at 09:57 By Ionut Arghire Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication. The post Roundcube Webmail Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Roundcube Webmail Vulnerability in Attackers’ Crosshairs Read More »

File Acquisition May Be Recorded as “FileAccessed” in Microsoft 365 (“M365”)

File Acquisition May Be Recorded as “FileAccessed” in Microsoft 365 (“M365”) 2026-09-24 at 15:30 By A recent trend has emerged where threat actor groups (e.g., ShinyHunters, PEAR, HELIX, etc.) have been leveraging phishing and vishing techniques to gain access to M365 email accounts. Through identity and token abuse, these actors have then automated large-scale file […]

File Acquisition May Be Recorded as “FileAccessed” in Microsoft 365 (“M365”) Read More »

Product showcase: Scamwise checks the red flags before you take the bait

Product showcase: Scamwise checks the red flags before you take the bait 2026-09-23 at 08:00 By Anamarija Pogorelec Scamwise is a free scam-checking service from Savi that examines suspicious messages, emails, websites, phone numbers, images, and real-world situations for signs of fraud. The service works in any web browser on desktop, mobile, or tablet, with […]

Product showcase: Scamwise checks the red flags before you take the bait Read More »

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) 2026-09-15 at 14:09 By Zeljka Zorz Attackers have leveraged a zero-day SQL injection vulnerability (CVE-2026-76461) to compromise Cisco Secure Email Gateway appliances, Cisco confirmed on Monday. The vendor’s Product Security Incident Response Team became aware of active exploitation of this vulnerability in September 2025, and has shared […]

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) Read More »

Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation 2026-09-15 at 08:18 By Eduard Kovacs An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges. The post Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation appeared first on SecurityWeek. This article is an […]

Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation Read More »

Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack 2026-09-11 at 15:48 By Eduard Kovacs Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking. The post Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack appeared first on SecurityWeek. This article […]

Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack Read More »

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks 2026-08-25 at 13:03 By Zeljka Zorz At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. About CVE-2026-73570 Zimbra Collaboration Suite (ZCS) is a communication and collaboration platform popular with organizations that need to have control over […]

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks Read More »

Beyond the Inbox: How BEC Leads to SSO Abuse

Beyond the Inbox: How BEC Leads to SSO Abuse 2026-08-13 at 20:40 By Jamie Mamroe and Federico Cedolini For years, many business email compromise (BEC) investigations have followed a familiar playbook: an attacker phishes credentials, logs into the victim’s mailbox, establishes persistence with inbox rules, monitors communications, and waits for an opportunity to steal money […]

Beyond the Inbox: How BEC Leads to SSO Abuse Read More »

The Infrastructure Relay: Inside Multi-Stage Phishing Redirection Chains

The Infrastructure Relay: Inside Multi-Stage Phishing Redirection Chains 2026-08-12 at 16:42 By Karla Agregado To stay ahead of evolving threats, LevelBlue utilizes a machine-learning-based URL scanner that constantly evaluates the digital landscape. We closely monitor VirusTotal for instances where LevelBlue acts as the sole detection layer — a crucial tactic for spotting new phishing campaigns […]

The Infrastructure Relay: Inside Multi-Stage Phishing Redirection Chains Read More »

Product showcase: Material unifies Google Workspace email, file & OAuth defense

Product showcase: Material unifies Google Workspace email, file & OAuth defense 2026-08-05 at 08:00 By Help Net Security Here’s an uncomfortable truth: the attack that gets you won’t look like an attack. It’ll look like a normal login, a normal file share, a normal permission request you clicked past without reading. You don’t have a […]

Product showcase: Material unifies Google Workspace email, file & OAuth defense Read More »

Weaponized Email AI Assistants Could Help Attackers Hijack Accounts

Weaponized Email AI Assistants Could Help Attackers Hijack Accounts 2026-08-04 at 16:54 By Kevin Townsend Researchers demonstrate how attackers could abuse built-in email chatbots to evade detection, impersonate trusted employees, compromise executive accounts, and facilitate financial fraud. The post Weaponized Email AI Assistants Could Help Attackers Hijack Accounts appeared first on SecurityWeek. This article is […]

Weaponized Email AI Assistants Could Help Attackers Hijack Accounts Read More »

Product showcase: Guardio Mobile Security turns breach alerts into a recovery plan

Product showcase: Guardio Mobile Security turns breach alerts into a recovery plan 2026-08-03 at 07:30 By Anamarija Pogorelec Guardio Mobile Security brings several protection features to iPhone and Android, allowing users to monitor exposed personal information, identify phishing attempts, and receive alerts about emerging threats from a single application. It is available on smartphones and […]

Product showcase: Guardio Mobile Security turns breach alerts into a recovery plan Read More »

AegisAI Raises $36 Million for AI-Powered Email Security

AegisAI Raises $36 Million for AI-Powered Email Security 2026-07-24 at 15:01 By SecurityWeek News The company has raised a total of $49 million in funding, including from Battery Ventures, Accel and Foundation Capital. The post AegisAI Raises $36 Million for AI-Powered Email Security appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

AegisAI Raises $36 Million for AI-Powered Email Security Read More »

StrongestLayer Raises $4.1 Million in Seed Funding Extension

StrongestLayer Raises $4.1 Million in Seed Funding Extension 2026-07-22 at 16:00 By Ionut Arghire The startup will use the fresh investment to accelerate its go-to-market strategy and to expand its platform. The post StrongestLayer Raises $4.1 Million in Seed Funding Extension appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

StrongestLayer Raises $4.1 Million in Seed Funding Extension Read More »

Zimbra Patches Critical Code Execution Vulnerability

Zimbra Patches Critical Code Execution Vulnerability 2026-07-13 at 13:03 By Ionut Arghire The flaw results in malicious code embedded in crafted emails being executed when the emails are opened. The post Zimbra Patches Critical Code Execution Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Zimbra Patches Critical Code Execution Vulnerability Read More »

Webinar Today: Why Email Security Keeps Failing

Webinar Today: Why Email Security Keeps Failing 2026-07-08 at 16:16 By SecurityWeek News Join the webinar as we break down why email-layer defenses alone can’t keep pace with the modern phishing ecosystem. The post Webinar Today: Why Email Security Keeps Failing appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Webinar Today: Why Email Security Keeps Failing Read More »

Securing the inbox: Where identity, brand and security meet

Securing the inbox: Where identity, brand and security meet 2026-07-06 at 09:00 By Mirko Zorz Getting a verified logo to appear next to your email has traditionally meant having to work with two separate entities. You have to work with a DMARC partner for setting up DMARC and BIMI, then use a trusted Certificate Authority […]

Securing the inbox: Where identity, brand and security meet Read More »

Synology issues critical fix for MailPlus Server vulnerabilities

Synology issues critical fix for MailPlus Server vulnerabilities 2026-06-26 at 13:57 By Zeljka Zorz Synology has has fixed critical vulnerabilities in MailPlus Server, a software package used to run private email infrastructure on Synology NAS devices. The security update fixes three flaws: CVE-2026-13136, stemming from faulty authorization checks, may allow remote attackers to read or […]

Synology issues critical fix for MailPlus Server vulnerabilities Read More »

Apple is bringing Hide My Email and Sign in with Apple under one domain

Apple is bringing Hide My Email and Sign in with Apple under one domain 2026-06-17 at 11:29 By Sinisa Markovic Apple will unify the email domains used by Sign in with Apple and iCloud+ Hide My Email under a shared domain, private.icloud.com, later this summer. Hide My Email is a service included with iCloud+, Apple’s […]

Apple is bringing Hide My Email and Sign in with Apple under one domain Read More »

Scroll to Top