Skip to content

Sam's News β€” email-security β€” 2026-08-21

Security

7.5 New SynkLoader malware distributed via Microsoft Teams phishing attacks

A previously unknown malware family called SynkLoader is spreading via Microsoft Teams phishing campaigns, using fake lock screens to steal credentials and grant attackers remote network access.

  • Malware family: SynkLoader
  • Distribution vector: Microsoft Teams phishing
  • Uses fake Windows lock screen to harvest credentials

Sources: BleepingComputer AI Web Searched, CyberInsider AI Web Searched

7.5 Google Docs Phishing Attack Installs Rogue Certificate Authority on Windows PCs

A phishing attack targeting Google Docs users has successfully installed a rogue certificate authority on Windows systems.

Sources: Redmondmag.com RSS

7 Business email compromise attack exploits session tokens to steal vendor payments

Attackers hijacked session tokens in a business email compromise campaign to intercept vendor payments.

Sources: PYMNTS.com RSS

6.5 EPA OIG Issues Fraud Alert on Business Email Compromise Attacks

The U.S. Environmental Protection Agency Office of Inspector General has issued a fraud alert highlighting the growing prevalence and cost of business email compromise attacks.

Sources: U.S. Environmental Protection Agency (.gov) Web Search

6.5 Agent Tesla v4 BEC campaign uses emoji obfuscation and fileless execution

Cybersecurity researchers document an Agent Tesla v4 business email compromise campaign that bypasses email security using emoji obfuscation and in-memory infostealer techniques.

Sources: KnowBe4 Blog Web Search

6.5 Attackers abuse Microsoft login system to camouflage phishing attacks

A phishing technique exploits Microsoft's legitimate authentication system, using real login pages to deceive users into granting account access.

Sources: Help Net Security Web Search

Law firm Foley Hoag LLP provides guidance on evolving legal implications and best practices for defending against business email compromise attacks.

Sources: Foley Hoag Web Search

5.5 Operation Asterix targets 885,000 phone numbers in cryptocurrency phishing campaign

A phishing campaign called Operation Asterix has targeted 885,000 phone numbers in attacks aimed at cryptocurrency users.

Sources: Crypto News Australia RSS Update to: Operation Asterix phishing campaign targets 885,000 phone numbers including Binance users

5.5 Cognitive security framework reduces phishing vulnerability through objective thinking

A cognitive security experiment demonstrates that applying a structured approach of naming, framing, and checking threats improves defense against phishing attacks.

Sources: HackerNoon Web Search