Skip to content

Sam's News β€” email-security β€” 2026-09-03

Security

7.5 Threat actors impersonate IT support via Microsoft Teams to breach enterprises

Microsoft Threat Intelligence documented a campaign where attackers impersonate IT support via Teams external collaboration to socially engineer remote access, then deploy obfuscated Node.js implants enabling persistent command execution and lateral movement. The campaign uses legitimate tools to blend into normal operations and precedes data theft, ransomware, and extortion.

  • Threat actors impersonate IT/helpdesk via Teams external collaboration
  • Deliver malicious MSI with portable Node.js runtime and obfuscated JavaScript implant
  • Implant enables C2, screenshots, PowerShell execution, WinRM lateral movement
  • Activity patterns suggest precursors to ransomware, extortion, data theft

Sources: Microsoft Security Blog AI Web Searched

7 Unicode smuggling technique adapted for email phishing evasion

Invisible Unicode tag characters (U+E0000 to U+E007F) previously used for AI prompt injection are now being repurposed to evade email filters in phishing attacks. A high-volume phishing campaign beginning February 9, 2026, uses this ASCII smuggling technique to split financial lure words and bypass email filters.

  • High-volume phishing campaign started February 9, 2026
  • Uses invisible Unicode tag characters (U+E0000–U+E007F) to split keywords like 'funding'
  • Technique adapted from AI prompt injection research
  • Microsoft Defender detections elevated for approximately three months
  • Most flagged messages caught by layered protections rather than single Unicode signals

Sources: Microsoft Security Blog AI Web Searched, Microsoft RSS

7 Text-based QR phishing technique bypasses email security and image scanners

A new phishing technique using text-based QR codes can evade traditional email security systems and image-based scanners.

Sources: cyberpress.org RSS

6.5 Global RMM phishing campaign targets 46 countries, with US as top victim

An RMM phishing campaign spanning 46 countries accounts for roughly 45% of observed activity targeting the United States.

Sources: The Hacker News RSS, SC Media RSS, thehackernews.com RSS

6.5 Microsoft Teams Voice Phishing Campaign Targets Corporate Networks

A voice phishing campaign is targeting corporate networks through Microsoft Teams.

Sources: Petri IT Knowledgebase RSS

6.5 Proofpoint Integrates OpenAI GPT Cyber Models into Falcon Security Platform

Proofpoint has incorporated OpenAI's GPT-based cybersecurity models into its Falcon security operations platform to accelerate threat investigation.

Sources: Proofpoint β€” Threat Insight RSS