Skip to content

Sam's News — email-security — 2026-08-24

Security

6 Attackers hijack legitimate Google Alerts in large-scale phishing campaign

Researchers discovered attackers abusing Google notifications and cloud services to deliver phishing emails that bypass traditional email security filters.

  • Campaign abuses Google Alerts and Google cloud services
  • Phishing emails bypass traditional email security defenses
  • Targets Microsoft login credentials and sensitive information
  • Reflects shift to abusing legitimate platforms vs. malicious infrastructure

Sources: TechRepublic Web Search Update to: Trusted Google Alerts hijacked in large-scale phishing campaign

6 Phishing attacks abuse Microsoft's legitimate authentication system to camouflage attacks

Attackers exploit Microsoft's real login infrastructure to craft convincing phishing attacks that trick users into granting account access.

Sources: Help Net Security Web Search Update to: Attackers abuse Microsoft login system to camouflage phishing attacks

6 EvilTokens Phishing Campaign Uses Encrypted HTML to Bypass Email Security

A new phishing campaign dubbed EvilTokens uses AES-GCM encrypted HTML and Microsoft Device Code tactics to hide account takeover pages until the browser renders them.

Sources: The Hacker News Web Search

6 Finance-Themed Phishing Wave: 40,000 Emails Impersonating SharePoint and e-Signing Services

Security researchers detected a wave of 40,000 phishing emails disguised as SharePoint and e-signing platforms targeting financial transactions and document exchanges.

Sources: Check Point Blog Web Search

6 Cryptocurrency Losses Exceed $40 Million Across Three Security Breaches

Three separate phishing and social engineering attacks have resulted in more than $40 million in combined cryptocurrency losses.

Sources: Bitcoin World RSS

6 ReliaQuest device trust framework successfully resists phishing attack

ReliaQuest's device trust security measure defended against a phishing attack, demonstrating its effectiveness.

Sources: SQ Magazine RSS

5 How to Identify Latest Phishing Scams; AI-Enhanced Attacks

Phishing attacks are evolving with criminals using generative AI to create linguistically sophisticated fraudulent emails.

  • Generative AI creates professionally styled phishing emails with legitimate-looking design
  • Attacks exploit Microsoft OAuth device code flow to bypass 2FA
  • Bypass targets legitimate device sign-in procedure without browser requirement
  • Modern attacks significantly more sophisticated than earlier phishing with poor grammar/design

Sources: PCWorld Web Search Update to: Identifying Modern Phishing Scams: Generative AI's Impact on Email Attacks

5 Phishing detection guide covers AI lures, ClickFix, and AiTM attacks in 2026

A 12-step, 90-minute guide teaches phishing detection methods addressing 2026 threat landscape including AI-generated lures and advanced social engineering.

Sources: https://tech-insider.org/ Web Search

5 Email defense strategy evolves to agent-versus-agent phishing combat

Traditional email defenses are becoming insufficient; the next generation of phishing defense will rely on AI agents battling social engineering attacks.

Sources: The Hacker News Web Search

5 QR-code phishing attacks ('quishing') evade corporate security measures

Quishing—QR-code-based phishing—has emerged as an effective technique that circumvents standard corporate email security controls.

  • Malicious QR codes were embedded in 11% of phishing emails in H1 2026
  • Quishing bypasses email filters because URLs are encoded visually rather than as readable text
  • QR codes redirect victims from protected corporate environments to personal mobile devices with fewer security controls
  • Attackers often combine quishing with trusted brand impersonation and urgency tactics to increase success rates

Sources: WeLiveSecurity Web Search Update to: QR Code Phishing (Quishing) Exploits Vulnerabilities in Corporate Security Defenses