Skip to content
Threat Feed

Tag

Email Security

8 briefs RSS
high advisory

Cross-Telemetry Correlation of Endpoint and Network Security Alerts

Detection engineering logic that correlates Elastic Defend endpoint alerts with network security events from PAN-OS, FortiGate, and Suricata to identify potentially compromised hosts based on multi-source telemetry.

Elastic Defend +5 correlation multi-datasource network-security endpoint-security phishing email-security
3t
high advisory

ASCII Smuggling Repurposed for Phishing Evasion

Attackers are repurposing the ASCII smuggling technique, originally intended for AI prompt injection, to embed invisible Unicode tag characters into phishing emails to bypass keyword-based security filters.

Microsoft Defender for Office 365 phishing evasion unicode email-security
1r 2t
low advisory

Denial of Service in parsedmarc via Unbounded Attachment Decompression

The parsedmarc library before version 11.0.1 is vulnerable to remote denial-of-service exploitation via crafted email attachments that trigger memory exhaustion through unbounded decompression.

parsedmarc denial-of-service vulnerability email-security
1c
high advisory

Multiple Vulnerabilities in SEPPmail Secure E-Mail Gateway

SEPPmail Secure E-Mail Gateway contains multiple vulnerabilities that an attacker can exploit to bypass security controls and achieve remote code execution on the appliance.

Secure E-Mail Gateway vulnerability email-security remote-code-execution
1t
high advisory

Sophos State of Ransomware 2026 Report Highlights Evolving Attack Vectors

The Sophos State of Ransomware 2026 report indicates that while median ransom payments are dropping, successful data encryption by ransomware attackers is climbing, with malicious email, phishing, and compromised credentials now surpassing exploited vulnerabilities as the primary initial access vectors, often leveraging identity-based attacks against critical systems like VPNs and firewalls.

ransomware trend-report initial-access identity-compromise email-security
8t
high advisory

Meta Business Manager Phishing Campaign Leveraging Legitimate Services

A threat actor group is actively conducting a phishing campaign since November 2025, abusing Meta's legitimate Business Account Manager service to send emails from noreply@business.facebook.com containing malicious Google Sites URLs that redirect to sophisticated phishing pages, ultimately aiming to steal Meta account credentials, MFA codes, personal and business contact information, and identification documents from targeted businesses, with recent evolutions including a Facebook Messenger chatbot and exfiltration to Telegram.

Meta Business Account Manager Service +4 phishing credential-theft cloud email-security
1r 5t 5i
high advisory

SonicWall Email Security Appliance Multiple Vulnerabilities

A remote, authenticated attacker with administrator rights can exploit multiple vulnerabilities in SonicWall Email Security Appliance to perform cross-site scripting, manipulate data, or cause a denial-of-service.

sonicwall email security xss dos data manipulation
2r 2t
medium advisory

Self-Hosted Email Threat Detection Tool

A user created a self-hosted email threat detection tool, named VerdictMail, employing IMAP IDLE for real-time monitoring and multi-stage enrichment via SPF, DKIM, DMARC, DNSBL, WHOIS, URLhaus, and VirusTotal, coupled with an LLM for threat assessment.

email-security threat-detection imap
2r