Monday 27 July 2026 03:55:08 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#Email security


The QR Trap: How Quishing Turns Email Into a Mobile Ambush

Published: 26 July 2026 10:04Category: Security Awareness & Social EngineeringAuthor: PATCHKNIGHT

QR-code phishing is growing fast because it moves the scam out of text filters and into the scan step, where a personal phone may become the attacker’s real launchpad.

Trusted Labels, Hidden Payloads: How a Fake Logistics Email Became a Malware Delivery Trap

Published: 25 July 2026 08:04Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A phishing run dressed up as shipping notices and tax-audit mail shows how attackers can turn everyday business trust into a credential-theft pipeline.

Inbox Security Gets Another Capital Injection as AI Tools Chase the Next Phish

Published: 24 July 2026 19:10Category: Technology, Innovation & Digital InfrastructureGeo: North America / USAAuthor: SECPULSE

AegisAI has raised $36 million, lifting its total funding to $49 million, in a round aimed at AI-powered email security and backed by Battery Ventures, Accel, and Foundation Capital.

Zimbra’s Hidden Trap: How a Webmail Flaw Became an Email-Exfiltration Tool

Published: 24 July 2026 15:32Category: Cyber Warfare & Nation-State OperationsGeo: North America / USAAuthor: AGONY

A view-triggered flaw in Zimbra Collaboration Suite shows how one vulnerable inbox interface can put mail history, credentials, and internal directories within reach of a determined operator.

Zimbra’s Hidden Trap Turned a Read Email into an Espionage Tool

Published: 24 July 2026 08:03Category: Cyber Warfare & Nation-State OperationsGeo: North America / USAAuthor: AGONY

A zero-day in Zimbra Classic UI let a malicious message run code inside the webmail session, shifting the attack goal from inbox access to broader account and identity theft.

The Inbox Was the Breach: How a Zimbra Zero-Day Turned Phishing into Mailbox Theft

Published: 23 July 2026 18:14Category: Cyber Warfare & Nation-State OperationsGeo: North America / USAAuthor: AGONY

A phishing campaign tied to a Zimbra zero-day shows how one compromised webmail layer can put months of correspondence and sensitive material at risk.

Microsoft Draws a New Line in the Inbox: Defending Email from AI Manipulation

Published: 23 July 2026 12:24Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: INTEGRITYFOX

Defender for Office 365 is now being used to blunt prompt injection, a reminder that enterprise email is becoming an input channel for assistants as much as a message stream for humans.

Microsoft Pushes Prompt Injection Defense Upstream, Into the Inbox

Published: 23 July 2026 12:12Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

Defender for Office 365 is now inspecting inbound email for hidden AI instructions before they can reach a mailbox or be consumed by Microsoft 365 Copilot.

Recovery Without Repair Leaves Ransomware Risk Alive

Published: 21 July 2026 18:17Category: Cyber Intelligence & Threat TrendsAuthor: GHOSTCOMPLY

A post-incident review points to a stubborn pattern: some organizations restore operations after ransomware, but leave email and patching weaknesses unresolved.

Zimbra’s Patch Sweep Shows How One Email Platform Can Hide Four Kinds of Risk

Published: 21 July 2026 13:10Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A critical refresh for Zimbra closes command injection, XSS, restriction bypass, and SSRF flaws, underscoring how email systems can fail across browser, policy, and server boundaries at once.

Phishing at the Identity Layer: Why APT42’s AI-Polished Lures Matter More Than the Malware

Published: 21 July 2026 12:58Category: Cyber Warfare & Nation-State OperationsGeo: Middle East / IranAuthor: AGONY

A reported espionage campaign tied to APT42 shows how AI-assisted phishing, cloud abuse, and PowerShell-heavy tooling can turn a single lure into access to government identities and sensitive mailboxes.

The Cheapest Crime in Cybersecurity Still Works: Why Phishing Keeps Slipping Past the Guardrails

Published: 19 July 2026 01:34Category: Security Awareness & Social EngineeringAuthor: NEURALSHIELD

Phishing stays effective because it abuses trust at scale, moving through email and other channels while defenders are forced to combine awareness, filtering, and stronger authentication.

One Email, One Browser Tab: Zimbra’s Critical Flaw Shrinks the Gap Between Inbox and Intrusion

Published: 13 July 2026 14:38Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

Zimbra has patched a critical bug tied to crafted emails, and the security lesson is blunt: when webmail renders hostile content inside a logged-in session, the attacker may not need anything more than a click.

When a Conference Invite Turns into a Malware Delivery Lane

Published: 13 July 2026 10:43Category: Cyber Warfare & Nation-State OperationsGeo: Asia / South KoreaAuthor: AGONY

A reported spear-phishing campaign borrowed real event details, then used an ISO container and process injection to move RokRAT onto Windows systems.

Roundcube’s Patch Exposes the Quiet Dangers Hidden in Webmail Parsing

Published: 10 July 2026 08:10Category: Vulnerabilities & Patch ManagementGeo: Europe / SwitzerlandAuthor: SECURESPECTER

A security update for Roundcube 1.7.2 shows how browser-facing mail code can turn plain text, URL fetching, and legacy attachments into high-risk attack surfaces.

The Phishing Page That Waited to Wake Up

Published: 08 July 2026 18:47Category: Security Awareness & Social EngineeringAuthor: PATCHKNIGHT

A ghost-phishing campaign is reportedly hiding malicious pages until they decrypt inside the browser, a trick that can leave traditional email and URL checks staring at an empty frame.

Why the Inbox Is No Longer the Whole Battlefield for Phishing

Published: 08 July 2026 16:10Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A webinar promotion about email security points to a larger problem: inbox controls help, but phishing now lives across identity, authentication, and user trust layers.

Webmail on the Edge: How Campus Inbox Systems Became a High-Value Foothold

Published: 08 July 2026 10:52Category: Cyber Warfare & Nation-State OperationsAuthor: AGONY

A new wave of university targeting shows why browser-based mail portals are no longer just communications tools - they can become the first trusted step into a much larger network.

One Webmail Flaw, Two Stages, and a Narrow Academic Target

Published: 08 July 2026 08:15Category: Cyber Warfare & Nation-State OperationsAuthor: AGONY

A suspected China-aligned cluster is tied to Roundcube exploitation, showing how a browser-side XSS bug can become a gateway into university mail infrastructure.

One Mail Backend, Millions of Credentials: Japan’s Telecom-Grade Exposure Problem

Published: 07 July 2026 18:32Category: Breaches & Data LeaksGeo: Asia / JapanAuthor: SECURERECLAIMER

A shared ISP email platform became the pressure point in a reported cyberattack, showing how one software flaw can turn routine mailbox infrastructure into a large-scale identity risk.