⤷ Title: The Invisible Code: How HTML QR Codes Are Slipping Past Email Filters
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 10 Jan 2026 10:30:46 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Credential Theft #Cybersecurity 2026 #email security #HTML Table #Infosec #phishing #QR code #Quishing #SANS #Social Engineering
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 10 Jan 2026 10:30:46 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Credential Theft #Cybersecurity 2026 #email security #HTML Table #Infosec #phishing #QR code #Quishing #SANS #Social Engineering
Information Security News
The Invisible Code: How HTML QR Codes Are Slipping Past Email Filters
Cyber adversaries have conceived an ingenious method to circumvent the security protocols utilized by email services to intercept malicious QR codes. Rather than employing conventional image files…
⤷ Title: Unpacking Microsoft Defender for Office 365: Day 5 SOC Triage—Email Authentication Deep Dive (SPF…
════════════════════════
𐀪 Author: Eugenia | Cybersecurity Awareness
════════════════════════
ⴵ Time: Fri, 16 Jan 2026 17:14:21 GMT
════════════════════════
⌗ Tags: #microsoft_defender #infosec #email_authentication #cyber_security_awareness #email_security
════════════════════════
𐀪 Author: Eugenia | Cybersecurity Awareness
════════════════════════
ⴵ Time: Fri, 16 Jan 2026 17:14:21 GMT
════════════════════════
⌗ Tags: #microsoft_defender #infosec #email_authentication #cyber_security_awareness #email_security
Medium
Unpacking Microsoft Defender for Office 365: Day 5 SOC Triage—Email Authentication Deep Dive (SPF…
Security teams receive 300+ phishing emails daily, with 80% using spoofed sender addresses. Email authentication protocols prevent…
⤷ Title: The “WorkMail Pivot”: Hackers Abuse AWS WorkMail to Bypass SES Sandbox
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:09:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Amazon SES #AWS #Cloud Security #CloudTrail Blind Spot #Email Security #phishing infrastructure #Rapid7 #SCP #truffleHog #WorkMail
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:09:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Amazon SES #AWS #Cloud Security #CloudTrail Blind Spot #Email Security #phishing infrastructure #Rapid7 #SCP #truffleHog #WorkMail
Daily CyberSecurity
The "WorkMail Pivot": Hackers Abuse AWS WorkMail to Bypass SES Sandbox
Attackers are bypassing AWS SES sandbox limits by pivoting to WorkMail. Rapid7 reveals how this abuse creates a blind spot for defenders.
⤷ Title: “Exfil Out&Look” Flaw Lets Spies Steal Emails via OWA Undetected
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:21:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Audit Logs #Cloud Security #data exfiltration #Email Security #Exfil Out&Look #Insider Threat #Microsoft 365 #Outlook Web Access #OWA #Varonis Threat Labs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:21:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Audit Logs #Cloud Security #data exfiltration #Email Security #Exfil Out&Look #Insider Threat #Microsoft 365 #Outlook Web Access #OWA #Varonis Threat Labs
Daily CyberSecurity
"Exfil Out&Look" Flaw Lets Spies Steal Emails via OWA Undetected
New "Exfil Out&Look" attack uses OWA add-ins to steal emails without leaving logs. Microsoft has no immediate fix for this blind spot.
⤷ Title: The Invisible Mosaic: How Tycoon’s HTML QR Codes and Teams Scams Are Blinding Modern Defenses
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 04:53:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Barracuda research #callback phishing #email security 2026 #Facebook copyright scam #Homoglyph Attack #HTML table QR #Microsoft Teams scam #Phishing_as_a_Service #QR Code Phishing #Tycoon toolkit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 04:53:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Barracuda research #callback phishing #email security 2026 #Facebook copyright scam #Homoglyph Attack #HTML table QR #Microsoft Teams scam #Phishing_as_a_Service #QR Code Phishing #Tycoon toolkit
Penetration Testing Tools
The Invisible Mosaic: How Tycoon’s HTML QR Codes and Teams Scams Are Blinding Modern Defenses
In the preceding month, analysts at Barracuda have identified a flurry of sophisticated email-borne incursions targeting corporations and
⤷ Title: Cloud-Hosted Trap: Phishers Use Vercel & Telegram to Bypass Filters
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 00:11:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cloud Security #Credential Harvesting #Dropbox Impersonation #Email Security #PDF Phishing #phishing #social engineering #Telegram bot #Vercel Blob #X_Labs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 00:11:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cloud Security #Credential Harvesting #Dropbox Impersonation #Email Security #PDF Phishing #phishing #social engineering #Telegram bot #Vercel Blob #X_Labs
Daily CyberSecurity
Cloud-Hosted Trap: Phishers Use Vercel & Telegram to Bypass Filters
Sophisticated phishing abuses Vercel Blob & PDFs to bypass filters. Stolen credentials are exfiltrated via Telegram bots. Learn how to spot this attack.
⤷ Title: Signed” Sealed, Delivered: Cybercriminals Abuse PayPal and Apple to Bypass Email Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:11:33 +0000
════════════════════════
⌗ Tags: #Cybercriminals #business email compromise #DKIM replay #DMARC #Email Security #INKY #Invoice Fraud #Kaseya #PayPal Scam #phishing #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:11:33 +0000
════════════════════════
⌗ Tags: #Cybercriminals #business email compromise #DKIM replay #DMARC #Email Security #INKY #Invoice Fraud #Kaseya #PayPal Scam #phishing #social engineering
Daily CyberSecurity
Signed" Sealed, Delivered: Cybercriminals Abuse PayPal and Apple to Bypass Email Security
Hackers abuse PayPal & Apple to send "perfect" phishing emails. Learn how DKIM Replay attacks bypass security filters & DMARC checks.
⤷ Title: Triple Threat Patched: Zimbra 10.1.16 Fixes XSS, XXE & LDAP Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 00:33:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Collaboration Suite #CSRF #Email Security #LDAP injection #Patch Alert #security update #XSS #xxe #Zimbra #Zimbra 10.1.16
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 00:33:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Collaboration Suite #CSRF #Email Security #LDAP injection #Patch Alert #security update #XSS #xxe #Zimbra #Zimbra 10.1.16
Daily CyberSecurity
Triple Threat Patched: Zimbra 10.1.16 Fixes XSS, XXE & LDAP Injection
Zimbra 10.1.16 patches critical XSS, XXE, and LDAP injection flaws. Update immediately to secure your email collaboration suite and restore PDF previews.
⤷ Title: Email Under Siege: Storm-2603 Exploits SmarterMail to Deploy Warlock Ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 00:28:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_23760 #CVE_2026_24423 #Email Security #living_off_the_land #Patch Alert #ReliaQuest #SmarterMail #Storm_2603 #Velociraptor #Warlock Ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 00:28:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_23760 #CVE_2026_24423 #Email Security #living_off_the_land #Patch Alert #ReliaQuest #SmarterMail #Storm_2603 #Velociraptor #Warlock Ransomware
Daily CyberSecurity
Email Under Siege: Storm-2603 Exploits SmarterMail to Deploy Warlock Ransomware
Storm-2603 exploits SmarterMail vulnerability CVE-2026-23760 to deploy Warlock ransomware. Upgrade to Build 9511 immediately to prevent system compromise.
⤷ Title: Hackers Use Jira Notifications to Bypass Spam Filters
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 18 Feb 2026 00:12:55 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Atlassian JIRA #Email Security #Enterprise Security #Keitaro TDS #Notification Abuse #phishing #SaaS Security #social engineering #spam campaign #Trend Micro
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 18 Feb 2026 00:12:55 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Atlassian JIRA #Email Security #Enterprise Security #Keitaro TDS #Notification Abuse #phishing #SaaS Security #social engineering #spam campaign #Trend Micro
Daily CyberSecurity
Hackers Use Jira Notifications to Bypass Spam Filters
Hackers abuse Atlassian Jira notifications to bypass spam filters. Trend Micro warns of scams targeting enterprise users via trusted alerts.