Phishing is no longer just noisy spam - it is becoming more organized, and AI is making some lures more convincing, more localized, and less dependent on obvious spelling mistakes.
A reported five-month campaign against a stock exchange executive’s Outlook mailbox shows how email access can matter more than broad network intrusion when the goal is intelligence gathering.
A months-long intrusion into a stock exchange executive’s Outlook mailbox shows how ordinary cloud tools can be repurposed to hide high-value email collection.
A suspected China-aligned cluster is using tax-, payroll-, and benefits-themed lures to deliver SilentRunLoader, a reminder that routine business emails can be weaponized before any visible breach begins.
A high-severity CRLF injection flaw in Laravel shows how a routine validation check can cross a protocol boundary and disturb outbound email handling.
A reported rise in phishing and ransomware activity points to a familiar attack chain, while generative AI remains a broader threat multiplier rather than a proven factor in these specific incidents.
Routine-looking email attachments are being used to stage VIP Keylogger through layered loaders and obfuscation, turning ordinary business workflow into a credential-theft path.
Roundcube Webmail has shipped security updates for eight vulnerabilities, including four rated high severity, underscoring how quickly a mail interface can become a convergence point for content rendering, plugins, and backend trust.
A 2026 DMARC benchmark shows that while authentication is widely discussed, enforcement remains rare enough to keep spoofed email a practical problem for defenders.
A new email-security startup is betting that specialized AI agents can inspect every message fast enough to help blunt phishing, impersonation, and business email compromise.
The GRU debate is not just about attribution; it is about how state power, identity abuse, and edge-device targeting fit into a long-running cyber strategy.
A critical memory-corruption flaw in GUARDIANWALL MailSuite puts enterprise email defenses in the crosshairs, with patching and exposure reduction now more urgent than routine maintenance.
Weak encryption and template injection in Salesforce Marketing Cloud exposed vast troves of subscriber emails to stealthy attackers-until a rapid emergency fix.
New security flaws in the Exim mail server software raise urgent questions about email security worldwide.
A wave of newly discovered Exim mail server vulnerabilities could let attackers crash systems or leak sensitive data-unless urgent patches are applied.
Attackers are exploiting a newly patched flaw in Zimbra’s email suite, exposing sensitive information across organizations.
A single compromised email address unravels a web of extortion, digital footprints, and cybercriminal market tactics.
A newly exploited Zimbra flaw puts thousands of organizations on high alert as CISA rings the alarm on widespread email compromise risks.