Sam's News — email-security — 2026-08-24¶
Security¶
6 Attackers hijack legitimate Google Alerts in large-scale phishing campaign¶
Researchers discovered attackers abusing Google notifications and cloud services to deliver phishing emails that bypass traditional email security filters.
- Campaign abuses Google Alerts and Google cloud services
- Phishing emails bypass traditional email security defenses
- Targets Microsoft login credentials and sensitive information
- Reflects shift to abusing legitimate platforms vs. malicious infrastructure
Sources: TechRepublic Web Search Update to: Trusted Google Alerts hijacked in large-scale phishing campaign
6 Phishing attacks abuse Microsoft's legitimate authentication system to camouflage attacks¶
Attackers exploit Microsoft's real login infrastructure to craft convincing phishing attacks that trick users into granting account access.
Sources: Help Net Security Web Search Update to: Attackers abuse Microsoft login system to camouflage phishing attacks
6 EvilTokens Phishing Campaign Uses Encrypted HTML to Bypass Email Security¶
A new phishing campaign dubbed EvilTokens uses AES-GCM encrypted HTML and Microsoft Device Code tactics to hide account takeover pages until the browser renders them.
Sources: The Hacker News Web Search
6 Finance-Themed Phishing Wave: 40,000 Emails Impersonating SharePoint and e-Signing Services¶
Security researchers detected a wave of 40,000 phishing emails disguised as SharePoint and e-signing platforms targeting financial transactions and document exchanges.
Sources: Check Point Blog Web Search
6 Cryptocurrency Losses Exceed $40 Million Across Three Security Breaches¶
Three separate phishing and social engineering attacks have resulted in more than $40 million in combined cryptocurrency losses.
Sources: Bitcoin World RSS
6 ReliaQuest device trust framework successfully resists phishing attack¶
ReliaQuest's device trust security measure defended against a phishing attack, demonstrating its effectiveness.
Sources: SQ Magazine RSS
5 How to Identify Latest Phishing Scams; AI-Enhanced Attacks¶
Phishing attacks are evolving with criminals using generative AI to create linguistically sophisticated fraudulent emails.
- Generative AI creates professionally styled phishing emails with legitimate-looking design
- Attacks exploit Microsoft OAuth device code flow to bypass 2FA
- Bypass targets legitimate device sign-in procedure without browser requirement
- Modern attacks significantly more sophisticated than earlier phishing with poor grammar/design
Sources: PCWorld Web Search Update to: Identifying Modern Phishing Scams: Generative AI's Impact on Email Attacks
5 Phishing detection guide covers AI lures, ClickFix, and AiTM attacks in 2026¶
A 12-step, 90-minute guide teaches phishing detection methods addressing 2026 threat landscape including AI-generated lures and advanced social engineering.
Sources: https://tech-insider.org/ Web Search
5 Email defense strategy evolves to agent-versus-agent phishing combat¶
Traditional email defenses are becoming insufficient; the next generation of phishing defense will rely on AI agents battling social engineering attacks.
Sources: The Hacker News Web Search
5 QR-code phishing attacks ('quishing') evade corporate security measures¶
Quishing—QR-code-based phishing—has emerged as an effective technique that circumvents standard corporate email security controls.
- Malicious QR codes were embedded in 11% of phishing emails in H1 2026
- Quishing bypasses email filters because URLs are encoded visually rather than as readable text
- QR codes redirect victims from protected corporate environments to personal mobile devices with fewer security controls
- Attackers often combine quishing with trusted brand impersonation and urgency tactics to increase success rates
Sources: WeLiveSecurity Web Search Update to: QR Code Phishing (Quishing) Exploits Vulnerabilities in Corporate Security Defenses