email security
5 stories
Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All
Security researchers Cory Solovewicz and Mike Sheward have inadvertently created honeypots by purchasing domains like noreply.us and deleteduser.com. Organizations are mistakenly sending sensitive data, including personal information, company secrets, and system credentials, to these domains, believing they are unmonitored. Both researchers are now working to notify affected entities and raise awareness about this widespread misconfiguration, highlighting the potential for malicious actors to exploit such vulnerabilities.

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
New research reveals that sophisticated CSS-based attacks can bypass webmail security measures, enabling attackers to steal sensitive information like passwords and session tokens. These techniques exploit vulnerabilities in popular email services including Outlook, Gmail, and Yahoo Mail, potentially leading to account takeovers and data breaches. The findings highlight the need for stricter sanitization and isolation of email content.

Attackers Use Text Salting to Evade AI-Powered Spam Filters
Cybersecurity firm Barracuda reports that attackers are increasingly using a technique called 'text salting' to bypass AI-driven email filters. This method involves embedding harmless-looking words within malicious emails to confuse machine-learning and LLM-based security tools. Barracuda has observed over a million phishing attacks employing this tactic since April.

Webinar tomorrow: Why modern email attacks require a new approach to defense
A webinar examines why modern email attacks require new defenses. It highlights behavioral AI for detecting phishing, business email compromise, and account takeover while reducing alert fatigue.

Cybercriminals Target Email Inboxes for Identity Theft
Cybercriminals are increasingly targeting email inboxes because they serve as a central hub for personal information and online accounts. Gaining access to an inbox can allow attackers to control other digital identities and access sensitive data.