Sam's News β email-security β 2026-09-20¶
Security¶
7.5 Phishing and BEC Attacks Exploiting Amazon SES¶
Attackers are exploiting Amazon SES's legitimate infrastructure to conduct phishing and business email compromise campaigns, bypassing email security measures through compromised accounts and misconfigured settings. Kaspersky research published in May 2026 documents specific examples of how the service enables fraudulent emails appearing to originate from trusted sources.
- Kaspersky research published May 2026
- Exploits compromised accounts and misconfigured SES settings
- Attackers impersonate business communications for fraud
Sources: Kaspersky Securelist AI Web Searched, Securelist Web Search
7 Ghost Phishing Wave Bypasses Traditional Email Security Defenses¶
The EvilTokens campaign uses AES-GCM encrypted HTML that hides malicious content from static URL checks, only decrypting after page load in the victim's browser. The attack targets businesses across the US and Europe using Microsoft Device Code Phishing to enable account takeover without stealing passwords directly.
- AES-GCM encryption bypasses network-level inspection
- Targets US and Europe: tech, manufacturing, education, banking, consulting, financial services, MSPs
- Phishing exposure rates: 75.6% consulting, 72.8% financial services, 71.9% manufacturing, 67.9% technology, 66.7% banking, 66.1% MSPs
- Microsoft Device Code Phishing enables M365 account takeover
- Requires sandbox analysis with in-browser decryption for detection
Sources: The Hacker News AI Web Searched, thehackernews.com Web Search
5.5 Business Email Compromise: Legal Trends and Defense Strategies¶
Legal frameworks and strategic defenses are evolving in response to business email compromise incidents.
Sources: Foley Hoag Web Search