Sam's News — email-security — 2026-08-18¶
Security¶
7.5 EvilTokens Phishing Campaign Bypasses Email Security with Encrypted HTML¶
EvilTokens exploits AES-GCM encryption and Microsoft Device Code Phishing to hide Microsoft 365 account takeover pages from email filters.
Sources: The Hacker News Web Search, The Hacker News Web Search Update to: EvilTokens Phishing Campaign Exploits Encrypted HTML and Device Code Phishing
7 Generative AI Enables More Convincing Phishing Email Creation¶
Criminals are leveraging generative AI to craft linguistically sophisticated phishing emails, making traditional phishing indicators harder to spot.
- AI-driven phishing now grammatically perfect, contextually relevant
- Evades traditional typo/formatting-based detection
- DMARC, domain monitoring, callback verification recommended
- Phishing-resistant MFA beyond SMS/push essential
Sources: PCWorld Web Search, PCWorld Web Search Update to: Generative AI Augmenting Phishing Attack Sophistication and Evasion
6.5 QR-code phishing ('quishing') bypasses corporate security defenses¶
QR-code phishing (quishing) is increasingly used to bypass traditional email security measures, exploiting gaps in corporate defenses.
Sources: WeLiveSecurity Web Search, WeLiveSecurity Web Search Update to: QR-code phishing attacks bypass corporate security defenses
6.5 2026 Email Security Report: AI's Role in Phishing and Defense¶
Artificial intelligence is transforming phishing attack sophistication and email defense strategies, with emerging threats detailed in the 2026 Email Security Report.
Sources: Kaseya Web Search, Kaseya Web Search
6.5 Security Awareness Training Significantly Reduces Phishing Success Rates¶
Human error accounts for roughly 95% of security breaches, but security awareness training demonstrably reduces phishing success rates.
Sources: EdTech Magazine Web Search, EdTech Magazine Web Search Update to: Security Awareness Training Significantly Reduces Phishing Susceptibility
6.5 Microsoft uncovers MacSync Stealer malware infrastructure with 30+ related domains¶
Microsoft researchers tracked MacSync Stealer malware by identifying consistent behavioral patterns across 30 rotating domains.
Sources: Microsoft Security Blog RSS
6 Secure Email Threat Defense earns AAA rating in SE Labs email security evaluation¶
Secure Email Threat Defense (ETD) achieved a 94% Total Accuracy Rating in the May 2026 SE Labs Advanced Email Security Evaluation.
Sources: Cisco Blogs Web Search, Cisco Blogs Web Search, Cisco Blogs Web Search
6 Business email compromise detection predicts attacks through compromised credentials analysis¶
Threat intelligence can detect business email compromise attacks by identifying stolen credentials before malicious emails are sent.
Sources: Group-IB Web Search Update to: Business Email Compromise Prevention Through Compromised Credential Detection
Email Security¶
6.5 1Password Warns Users of Targeted Email Phishing Attack¶
Password manager 1Password is alerting users about a phishing campaign targeting its customer base via email.
Sources: News18 RSS
5.5 Seven Reasons Organizations Add Email Security Beyond Microsoft 365 E5¶
Organizations are adopting third-party email security tools beyond Microsoft 365 E5's native Defender for Office 365 Plan 2.
Sources: Security Boulevard RSS, Security Boulevard Web Search, Security Boulevard Web Search