Lead Analysts: Prabhakaran Ravichandhiran, Jeewan Singh Jalal
Reading view
Microsoft Observed 7.6 Billion Phishing Emails in Q2 2026
Researchers at Microsoft warn that phishing emails are still the top initial access vector, with more than 2 billion phishing threats detected each month during the second quarter of 2026.
The Blind Spot: How βBulletproofβ Phishing Redirectors Slip Past SEGs
By Shikhar Dalela and Jeewan Singh Jalal
The operators named the kit themselves.
Buried inside compromised legitimate websites, the hidden staging directory is sometimes literally called β/.bulletproofβ, and the PHP session cookie the kit sets on every visitor is named βbp_redir_sess.β The βbpβ stands for bulletproof, which is an unusual degree of candor from a threat actor whose entire design philosophy is concealment.
Introducing The Hybrid Nudge Experience: Outbound Email Security Built for Your Risk Appetite
When it comes to outbound email security, every organization operates under different operational constraints and security requirements. Some security teams prioritize in-app nudges and coaching to catch risky behavior the moment an email is drafted. Others want to avoid friction, particularly for executives, sales teamsΒ or mobile-first employees who rarely interact with desktop add-ins.
Elevating the SOC Experience: Smarter Automation, Richer Threat Intelligence, and AI-Native Investigation
Security operations teams face a constant balancing act: stopping sophisticated email threats, maintaining visibility across their attack surface and keeping administrative workflows running smoothly. When security tools operate in silos or rely on rigid, manual processes, friction builds up quickly. This friction consumes valuable time that analysts could spend on higher-priority initiatives.
Trust, Verify, Protect: Modernizing Email Security for the Cloud
Picture this: Your company just fell victim to a massive data breach. The culprit wasn't a sophisticated malware strain, a zero-day exploit, or a compromised firewall. It was a perfectly legitimate-looking login from a VPβs account, originating from an unrecognized IP address, requesting an urgent wire transfer via a spotless, text-only email.
Static DLP Is Leaving You in the Dark: Why Itβs Time for Intelligent, Self-Serve Outbound DLP and Misdirected Content Analysis
When we think about email security, our minds almost always jump to the inbound threats: the sophisticated phishing lures, the AI-generated business email compromise (BEC) attacks, and the malicious attachments knocking at the perimeter.