Skip to content

Sam's News β€” email-security β€” 2026-08-17

Security

8 NSA Alerts on Russian State-Sponsored Phishing Campaign Targeting Zimbra Users

The NSA and partner agencies issued an alert on Russian state-sponsored phishing attacks targeting Zimbra Collaboration Suite users.

Sources: National Security Agency (NSA) (.gov) Web Search, National Security Agency (NSA) (.gov) Web Search, National Security Agency (NSA) (.gov) Web Search, National Security Agency (NSA) (.gov) Web Search Update to: NSA Alerts on Russian State-Backed Phishing Campaign Targeting Zimbra Collaboration Suite

7.5 EvilTokens Phishing Campaign Exploits Encrypted HTML and Device Code Phishing

A new phishing attack called EvilTokens uses encrypted HTML and Microsoft Device Code phishing to hide credential-harvesting pages from detection until rendered in a browser.

Sources: The Hacker News Web Search, The Hacker News Web Search, The Hacker News Web Search, The Hacker News Web Search Update to: EvilTokens Ghost Phishing Campaign Bypasses Traditional Email Security

7 Business Email Compromise Prevention Through Compromised Credential Detection

Most BEC attacks begin with compromised credentials rather than malicious email, and Group-IB demonstrates threat intelligence can identify compromises proactively.

Sources: Group-IB Web Search, Group-IB Web Search, Group-IB Web Search, Group-IB Web Search Update to: Business Email Compromise Detection Using Threat Intelligence

7 Generative AI Augmenting Phishing Attack Sophistication and Evasion

Phishing campaigns increasingly use generative AI to create emails that are linguistically indistinguishable from legitimate communications.

  • AI-driven phishing now grammatically perfect, contextually relevant
  • Evades traditional typo/formatting-based detection
  • DMARC, domain monitoring, callback verification recommended
  • Phishing-resistant MFA beyond SMS/push essential

Sources: PCWorld Web Search, PCWorld Web Search, PCWorld Web Search, PCWorld Web Search Update to: AI-Enhanced Phishing: Cybercriminals' New Tactics and Defensive Countermeasures

7 QR-code phishing attacks bypass corporate security defenses

Security researchers demonstrate how QR-code-based phishing attacks can bypass traditional corporate security controls.

Sources: WeLiveSecurity Web Search, WeLiveSecurity Web Search, WeLiveSecurity Web Search, WeLiveSecurity RSS

6.5 Email Threat Landscape Q2 2026: Post-Microsoft DCU Effects

Second-quarter 2026 email security trends reveal ongoing threats stemming from fallout of Microsoft's Digital Crimes initiative and evolving attack patterns.

Sources: Microsoft Web Search, Microsoft Web Search, Microsoft Web Search, Microsoft Web Search Update to: Q2 2026 Email Threat Landscape Report

6.5 Security Awareness Training Significantly Reduces Phishing Susceptibility

Human error accounts for approximately 95% of breaches according to IBM, and security awareness training is an effective countermeasure.

Sources: EdTech Magazine Web Search, EdTech Magazine Web Search, EdTech Magazine Web Search, EdTech Magazine Web Search Update to: Security Awareness Training Reduces Phishing Success

6 Cisco Secure Email Threat Defense Achieves FedRAMP High Certification

Cisco announced that Secure Email Threat Defense has achieved FedRAMP Class D (High) certification for federal compliance.

  • Cisco Secure Email Threat Defense received FedRAMP Class D (High) certification on August 10, 2026
  • FedRAMP authorization requires stringent security controls, continuous monitoring, and independent third-party assessments
  • The solution is available in both API-based supplemental control and inline gateway-level protection modes
  • Certification mandates persistent scrutiny and continuous authorization, not one-time audits

Sources: Cisco Blogs Web Search, Cisco Blogs Web Search, Cisco Blogs Web Search Update to: Cisco Secure Email Threat Defense Achieves FedRAMP Class D (High) Certification

6 MSP Email Security Operations: Detection, Resilience, and Operational Scalability

Managed service providers are shifting email security strategy from pure detection toward operational resilience, accepting that threats will penetrate and focusing on rapid response.

Sources: ChannelE2E Web Search, ChannelE2E Web Search, ChannelE2E Web Search, ChannelE2E Web Search Update to: Email Resilience for MSPs: Security as Operations Challenge

6 AI-Enhanced Phishing Detection and Defense: Best Practices Against Copycat Domains

CDK and others outline how to combat AI-driven phishing using domain spoofing detection and email security best practices.

Sources: CDK Global Web Search