Application securityMicrosoft 365 mailbox rules abused for exfiltration, persistenceSteve ZurierApril 13, 2026Attackers abuse Microsoft 365 mailbox rules to hide activity, steal data, and persist after password resets.
Email securityZephyr Energy loses £700,000 in payment fraud attackSC StaffApril 10, 2026The incident, disclosed in a regulatory filing, involved a business email compromise attack where cybercriminals likely infiltrated email or accounting systems to alter payment details.
MalwareMalicious email delivers advanced malware with privilege escalation and evasion tacticsSC StaffApril 7, 2026The attack chain begins with a user receiving an email containing a URL that downloads an encoded .cmd file.
Email security5 email threats to watch as identity and AI attacks evolve Mick Leach April 6, 2026Attacks on email that exploit OAuth consent, lateral phishing, and AI payroll fraud top the list.
Email securityBreaking the trade-off: Full email security without deployment frictionPaul WagenseilApril 3, 2026How API-based security is redefining email protection in the face of escalating human risk.
RansomwareHighly evasive spear-phishing campaign targeting senior execs ‘neutralizes’ MFALaura FrenchApril 3, 2026The campaign leverages a newly-discovered phishing kit called VENOM.
RSACInfoblox’s Craig Sanderson breaks down the newly finalized NIST SP 800-81SC StaffApril 2, 2026Craig Sanderson dives into the newly finalized NIST SP 800-81 as it marks a pivotal shift in DNS security.