Sam's News — email-security — 2026-10-07¶
Security¶
7 New Ghost Phishing Wave Breaks Traditional Email Security Defenses¶
The EvilTokens-attributed campaign uses "ghost phishing" to bypass email security by encrypting malicious HTML with AES-GCM, rendering in victim browsers only after decryption. Attacks exploit Microsoft Device Code phishing and target 194 countries across technology, finance, manufacturing, and security sectors.
- 'Ghost phishing' technique encrypts malicious HTML with AES-GCM, defeating static URL checks
- Bypasses network-level security controls until decryption in victim browser
- Microsoft Device Code phishing tricks users into authorizing account access without password theft
- SOCRadar verified 86,644+ compromised devices across 194 countries
- Phishing exposure rates: consulting 75.6%, financial services 72.8%, manufacturing 71.9%, technology 67.9%, banking 66.7%, MSSPs 66.1%
Sources: The Hacker News AI Web Searched, KLSE Screener Web Search
6 Abnormal AI Expands Email Security: Detection, Data Protection, and Phishing Simulation¶
Abnormal AI announces expanded email security platform combining threat detection, data protection, and user training.
Sources: Help Net Security Web Search
5.5 Kaspersky Detects Microsoft-Themed Phishing Campaign¶
Kaspersky has identified a phishing campaign impersonating Microsoft links to steal credentials.
Sources: KLSE Screener RSS