❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 15 September 2026Hacking and InfoSec

Phishing Emails Use New Technique to Bypass Microsoft 365 Security Filters

15 September 2026 at 12:00

Threat actors are using phishing emails with blank SMTP sender fields to bypass Microsoft 365 security filters, according to researchers at ReliaQuest.

Microsoft 365 Exchange Online uses a feature called β€œRejectDirectSend” to block unauthenticated Direct Send emails from an organization’s trusted domain. If an attacker omits the domain field from these emails, however, RejectDirectSend will no longer block the messages. Attackers can therefore exploit this technique to impersonate internal users.

Before yesterdayHacking and InfoSec

The Blind Spot: How β€œBulletproof” Phishing Redirectors Slip Past SEGs

10 August 2026 at 12:00

By Shikhar Dalela and Jeewan Singh Jalal

The operators named the kit themselves.

Buried inside compromised legitimate websites, the hidden staging directory is sometimes literally called β€œ/.bulletproof”, and the PHP session cookie the kit sets on every visitor is named β€œbp_redir_sess.” The β€œbp” stands for bulletproof, which is an unusual degree of candor from a threat actor whose entire design philosophy is concealment.

Inside the OS-Aware Phishing Kit Profiling Your Device

30 July 2026 at 09:00

Lead Analysts: Prabhakaran Ravichandhiran and Jeewan Singh Jalal

Most phishing attacks pick a target and commit to a tactic. This one picks the tactic based on the target, which happens dynamically, per device, in milliseconds, without the victim ever knowing a decision was made.

Introducing The Hybrid Nudge Experience: Outbound Email Security Built for Your Risk Appetite

24 July 2026 at 08:00

When it comes to outbound email security, every organization operates under different operational constraints and security requirements. Some security teams prioritize in-app nudges and coaching to catch risky behavior the moment an email is drafted. Others want to avoid friction, particularly for executives, sales teamsΒ or mobile-first employees who rarely interact with desktop add-ins.

Elevating the SOC Experience: Smarter Automation, Richer Threat Intelligence, and AI-Native Investigation

23 July 2026 at 17:00

Security operations teams face a constant balancing act: stopping sophisticated email threats, maintaining visibility across their attack surface and keeping administrative workflows running smoothly. When security tools operate in silos or rely on rigid, manual processes, friction builds up quickly. This friction consumes valuable time that analysts could spend on higher-priority initiatives.

Trust, Verify, Protect: Modernizing Email Security for the Cloud

16 July 2026 at 09:00

Picture this: Your company just fell victim to a massive data breach. The culprit wasn't a sophisticated malware strain, a zero-day exploit, or a compromised firewall. It was a perfectly legitimate-looking login from a VP’s account, originating from an unrecognized IP address, requesting an urgent wire transfer via a spotless, text-only email.

5 Essential Cybersecurity Defenses for Cloud Email Security

2 July 2026 at 12:00

Cloud email has become the center of modern business. Regardless of your organization's industry or size, email connects employees, customers, vendors, executives, financial systemsΒ and critical business processes.

❌
❌