Skip to content

Sam's News — email-security — 2026-10-07

Security

7 New Ghost Phishing Wave Breaks Traditional Email Security Defenses

The EvilTokens-attributed campaign uses "ghost phishing" to bypass email security by encrypting malicious HTML with AES-GCM, rendering in victim browsers only after decryption. Attacks exploit Microsoft Device Code phishing and target 194 countries across technology, finance, manufacturing, and security sectors.

  • 'Ghost phishing' technique encrypts malicious HTML with AES-GCM, defeating static URL checks
  • Bypasses network-level security controls until decryption in victim browser
  • Microsoft Device Code phishing tricks users into authorizing account access without password theft
  • SOCRadar verified 86,644+ compromised devices across 194 countries
  • Phishing exposure rates: consulting 75.6%, financial services 72.8%, manufacturing 71.9%, technology 67.9%, banking 66.7%, MSSPs 66.1%

Sources: The Hacker News AI Web Searched, KLSE Screener Web Search

6 Abnormal AI Expands Email Security: Detection, Data Protection, and Phishing Simulation

Abnormal AI announces expanded email security platform combining threat detection, data protection, and user training.

Sources: Help Net Security Web Search

5.5 Kaspersky Detects Microsoft-Themed Phishing Campaign

Kaspersky has identified a phishing campaign impersonating Microsoft links to steal credentials.

Sources: KLSE Screener RSS