email security

Beyond the Inbox: How BEC Leads to SSO Abuse

Beyond the Inbox: How BEC Leads to SSO Abuse 2026-08-13 at 20:40 By Jamie Mamroe and Federico Cedolini For years, many business email compromise (BEC) investigations have followed a familiar playbook: an attacker phishes credentials, logs into the victim’s mailbox, establishes persistence with inbox rules, monitors communications, and waits for an opportunity to steal money […]

Beyond the Inbox: How BEC Leads to SSO Abuse Read More »

The Infrastructure Relay: Inside Multi-Stage Phishing Redirection Chains

The Infrastructure Relay: Inside Multi-Stage Phishing Redirection Chains 2026-08-12 at 16:42 By Karla Agregado To stay ahead of evolving threats, LevelBlue utilizes a machine-learning-based URL scanner that constantly evaluates the digital landscape. We closely monitor VirusTotal for instances where LevelBlue acts as the sole detection layer — a crucial tactic for spotting new phishing campaigns

The Infrastructure Relay: Inside Multi-Stage Phishing Redirection Chains Read More »

Product showcase: Material unifies Google Workspace email, file & OAuth defense

Product showcase: Material unifies Google Workspace email, file & OAuth defense 2026-08-05 at 08:00 By Help Net Security Here’s an uncomfortable truth: the attack that gets you won’t look like an attack. It’ll look like a normal login, a normal file share, a normal permission request you clicked past without reading. You don’t have a

Product showcase: Material unifies Google Workspace email, file & OAuth defense Read More »

Weaponized Email AI Assistants Could Help Attackers Hijack Accounts

Weaponized Email AI Assistants Could Help Attackers Hijack Accounts 2026-08-04 at 16:54 By Kevin Townsend Researchers demonstrate how attackers could abuse built-in email chatbots to evade detection, impersonate trusted employees, compromise executive accounts, and facilitate financial fraud. The post Weaponized Email AI Assistants Could Help Attackers Hijack Accounts appeared first on SecurityWeek. This article is

Weaponized Email AI Assistants Could Help Attackers Hijack Accounts Read More »

Product showcase: Guardio Mobile Security turns breach alerts into a recovery plan

Product showcase: Guardio Mobile Security turns breach alerts into a recovery plan 2026-08-03 at 07:30 By Anamarija Pogorelec Guardio Mobile Security brings several protection features to iPhone and Android, allowing users to monitor exposed personal information, identify phishing attempts, and receive alerts about emerging threats from a single application. It is available on smartphones and

Product showcase: Guardio Mobile Security turns breach alerts into a recovery plan Read More »

AegisAI Raises $36 Million for AI-Powered Email Security

AegisAI Raises $36 Million for AI-Powered Email Security 2026-07-24 at 15:01 By SecurityWeek News The company has raised a total of $49 million in funding, including from Battery Ventures, Accel and Foundation Capital. The post AegisAI Raises $36 Million for AI-Powered Email Security appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

AegisAI Raises $36 Million for AI-Powered Email Security Read More »

StrongestLayer Raises $4.1 Million in Seed Funding Extension

StrongestLayer Raises $4.1 Million in Seed Funding Extension 2026-07-22 at 16:00 By Ionut Arghire The startup will use the fresh investment to accelerate its go-to-market strategy and to expand its platform. The post StrongestLayer Raises $4.1 Million in Seed Funding Extension appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

StrongestLayer Raises $4.1 Million in Seed Funding Extension Read More »

Zimbra Patches Critical Code Execution Vulnerability

Zimbra Patches Critical Code Execution Vulnerability 2026-07-13 at 13:03 By Ionut Arghire The flaw results in malicious code embedded in crafted emails being executed when the emails are opened. The post Zimbra Patches Critical Code Execution Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Zimbra Patches Critical Code Execution Vulnerability Read More »

Webinar Today: Why Email Security Keeps Failing

Webinar Today: Why Email Security Keeps Failing 2026-07-08 at 16:16 By SecurityWeek News Join the webinar as we break down why email-layer defenses alone can’t keep pace with the modern phishing ecosystem. The post Webinar Today: Why Email Security Keeps Failing appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Webinar Today: Why Email Security Keeps Failing Read More »

Securing the inbox: Where identity, brand and security meet

Securing the inbox: Where identity, brand and security meet 2026-07-06 at 09:00 By Mirko Zorz Getting a verified logo to appear next to your email has traditionally meant having to work with two separate entities. You have to work with a DMARC partner for setting up DMARC and BIMI, then use a trusted Certificate Authority

Securing the inbox: Where identity, brand and security meet Read More »

Synology issues critical fix for MailPlus Server vulnerabilities

Synology issues critical fix for MailPlus Server vulnerabilities 2026-06-26 at 13:57 By Zeljka Zorz Synology has has fixed critical vulnerabilities in MailPlus Server, a software package used to run private email infrastructure on Synology NAS devices. The security update fixes three flaws: CVE-2026-13136, stemming from faulty authorization checks, may allow remote attackers to read or

Synology issues critical fix for MailPlus Server vulnerabilities Read More »

Apple is bringing Hide My Email and Sign in with Apple under one domain

Apple is bringing Hide My Email and Sign in with Apple under one domain 2026-06-17 at 11:29 By Sinisa Markovic Apple will unify the email domains used by Sign in with Apple and iCloud+ Hide My Email under a shared domain, private.icloud.com, later this summer. Hide My Email is a service included with iCloud+, Apple’s

Apple is bringing Hide My Email and Sign in with Apple under one domain Read More »

Proxmox releases Mail Gateway 9.1 with quarantine and backup encryption changes

Proxmox releases Mail Gateway 9.1 with quarantine and backup encryption changes 2026-06-11 at 20:18 By Anamarija Pogorelec Proxmox Mail Gateway 9.1 adds updated system components, changes to the spam quarantine interface, and encryption for backups. It works as a mail proxy positioned between the firewall and internal mail servers, screening incoming and outgoing traffic for

Proxmox releases Mail Gateway 9.1 with quarantine and backup encryption changes Read More »

Ocean Emerges From Stealth With $28M for Agentic Email Security Platform

Ocean Emerges From Stealth With $28M for Agentic Email Security Platform 2026-05-21 at 15:24 By SecurityWeek News The company has developed a platform that uses specialized AI agents to inspect every incoming message. The post Ocean Emerges From Stealth With $28M for Agentic Email Security Platform appeared first on SecurityWeek. This article is an excerpt

Ocean Emerges From Stealth With $28M for Agentic Email Security Platform Read More »

Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild

Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild 2026-05-15 at 15:32 By Eduard Kovacs Microsoft has shared mitigations for CVE-2026-42897 until a permanent patch can be released for affected Exchange Server versions. The post Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt

Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild Read More »

Microsoft Patches Critical Zero-Click Outlook Vulnerability Threatening Enterprises

Microsoft Patches Critical Zero-Click Outlook Vulnerability Threatening Enterprises 2026-05-13 at 13:33 By Eduard Kovacs CVE-2026-40361 is similar to a vulnerability found a decade ago, BadWinmail, which at the time was dubbed an “enterprise killer”. The post Microsoft Patches Critical Zero-Click Outlook Vulnerability Threatening Enterprises appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Microsoft Patches Critical Zero-Click Outlook Vulnerability Threatening Enterprises Read More »

UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware

UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware 2026-04-27 at 13:55 By Ionut Arghire The threat actor infected victims with the Snow malware family – Snowbelt, Snowglaze, and Snowbasin – for persistent access. The post UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware appeared first on SecurityWeek. This article is an

UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware Read More »

The Behavioral Shift: Why Trusted Relationships Are the Newest Attack Surface

The Behavioral Shift: Why Trusted Relationships Are the Newest Attack Surface 2026-04-23 at 14:17 By Kevin Townsend New analysis from Abnormal AI reveals how attackers have abandoned technical exploits to weaponize routine workflows and internal trust. The post The Behavioral Shift: Why Trusted Relationships Are the Newest Attack Surface appeared first on SecurityWeek. This article

The Behavioral Shift: Why Trusted Relationships Are the Newest Attack Surface Read More »

Scroll to Top