Sam's News β email-security β 2026-08-17¶
Security¶
8 NSA Alerts on Russian State-Sponsored Phishing Campaign Targeting Zimbra Users¶
The NSA and partner agencies issued an alert on Russian state-sponsored phishing attacks targeting Zimbra Collaboration Suite users.
Sources: National Security Agency (NSA) (.gov) Web Search, National Security Agency (NSA) (.gov) Web Search, National Security Agency (NSA) (.gov) Web Search, National Security Agency (NSA) (.gov) Web Search Update to: NSA Alerts on Russian State-Backed Phishing Campaign Targeting Zimbra Collaboration Suite
7.5 EvilTokens Phishing Campaign Exploits Encrypted HTML and Device Code Phishing¶
A new phishing attack called EvilTokens uses encrypted HTML and Microsoft Device Code phishing to hide credential-harvesting pages from detection until rendered in a browser.
Sources: The Hacker News Web Search, The Hacker News Web Search, The Hacker News Web Search, The Hacker News Web Search Update to: EvilTokens Ghost Phishing Campaign Bypasses Traditional Email Security
7 Business Email Compromise Prevention Through Compromised Credential Detection¶
Most BEC attacks begin with compromised credentials rather than malicious email, and Group-IB demonstrates threat intelligence can identify compromises proactively.
Sources: Group-IB Web Search, Group-IB Web Search, Group-IB Web Search, Group-IB Web Search Update to: Business Email Compromise Detection Using Threat Intelligence
7 Generative AI Augmenting Phishing Attack Sophistication and Evasion¶
Phishing campaigns increasingly use generative AI to create emails that are linguistically indistinguishable from legitimate communications.
- AI-driven phishing now grammatically perfect, contextually relevant
- Evades traditional typo/formatting-based detection
- DMARC, domain monitoring, callback verification recommended
- Phishing-resistant MFA beyond SMS/push essential
Sources: PCWorld Web Search, PCWorld Web Search, PCWorld Web Search, PCWorld Web Search Update to: AI-Enhanced Phishing: Cybercriminals' New Tactics and Defensive Countermeasures
7 QR-code phishing attacks bypass corporate security defenses¶
Security researchers demonstrate how QR-code-based phishing attacks can bypass traditional corporate security controls.
Sources: WeLiveSecurity Web Search, WeLiveSecurity Web Search, WeLiveSecurity Web Search, WeLiveSecurity RSS
6.5 Email Threat Landscape Q2 2026: Post-Microsoft DCU Effects¶
Second-quarter 2026 email security trends reveal ongoing threats stemming from fallout of Microsoft's Digital Crimes initiative and evolving attack patterns.
Sources: Microsoft Web Search, Microsoft Web Search, Microsoft Web Search, Microsoft Web Search Update to: Q2 2026 Email Threat Landscape Report
6.5 Security Awareness Training Significantly Reduces Phishing Susceptibility¶
Human error accounts for approximately 95% of breaches according to IBM, and security awareness training is an effective countermeasure.
Sources: EdTech Magazine Web Search, EdTech Magazine Web Search, EdTech Magazine Web Search, EdTech Magazine Web Search Update to: Security Awareness Training Reduces Phishing Success
6 Cisco Secure Email Threat Defense Achieves FedRAMP High Certification¶
Cisco announced that Secure Email Threat Defense has achieved FedRAMP Class D (High) certification for federal compliance.
- Cisco Secure Email Threat Defense received FedRAMP Class D (High) certification on August 10, 2026
- FedRAMP authorization requires stringent security controls, continuous monitoring, and independent third-party assessments
- The solution is available in both API-based supplemental control and inline gateway-level protection modes
- Certification mandates persistent scrutiny and continuous authorization, not one-time audits
Sources: Cisco Blogs Web Search, Cisco Blogs Web Search, Cisco Blogs Web Search Update to: Cisco Secure Email Threat Defense Achieves FedRAMP Class D (High) Certification
6 MSP Email Security Operations: Detection, Resilience, and Operational Scalability¶
Managed service providers are shifting email security strategy from pure detection toward operational resilience, accepting that threats will penetrate and focusing on rapid response.
Sources: ChannelE2E Web Search, ChannelE2E Web Search, ChannelE2E Web Search, ChannelE2E Web Search Update to: Email Resilience for MSPs: Security as Operations Challenge
6 AI-Enhanced Phishing Detection and Defense: Best Practices Against Copycat Domains¶
CDK and others outline how to combat AI-driven phishing using domain spoofing detection and email security best practices.
Sources: CDK Global Web Search