Sam's News — email-security — 2026-09-28¶
Security¶
7 Ghost Phishing Attacks Evade Traditional Email Security Defenses¶
Ghost phishing attacks using the EvilTokens campaign bypass traditional email security by encrypting malicious HTML with AES-GCM, keeping content hidden during static inspection until it decrypts in a victim's browser. The campaign uses Microsoft Device Code Phishing to trick users into authorizing account access without password theft, targeting 75.6% of consulting, 72.8% of financial services, and 71.9% of manufacturing organizations.
- EvilTokens campaign uses AES-GCM encrypted HTML to evade static URL checks
- Content decrypts only in victim's browser, creating visibility gap
- Microsoft Device Code Phishing used to bypass password requirement
- Phishing exposure 2026: 75.6% consulting, 72.8% financial services, 71.9% manufacturing
Sources: The Hacker News AI Web Searched
6.5 Kaspersky Alerts on Active Phishing Campaign Impersonating Zoom and Docusign¶
Kaspersky researchers documented an active phishing email campaign impersonating legitimate Zoom and DocuSign communications to steal credentials.
Sources: TahawulTech.com RSS
6.5 NeedyMantis: Modular post-compromise malware framework discovered by Microsoft¶
Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions with custom loaders and encrypted archives for persistent access.
Sources: Microsoft Security Blog RSS
4 Third-Party Testing Validates Email Security Defense Effectiveness¶
Independent security testing confirms strong threat detection and prevention capabilities of a commercial email security solution.
Sources: Cisco Blogs Web Search