Visualização normal

Antes de ontemStream principal
  • ✇Cybersecurity News
  • Gmail Verified Sender Program Launch 2026 Do Son
    Google launches the Gmail Verified Sender Program, allowing political campaigns to bypass spam filters ahead of the 2026 US Mid-term Elections. Related Posts: Telegram Applies for .gram Domain to Give Every User Their Own TLD GitHub Outage Postmortem: Retry Storm and Copilot Auth Overload Explained OpenAI Astra Security Model: Pausing Development for Safety The post Gmail Verified Sender Program Launch 2026 appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Roundcube Patches RCE and SSRF Flaws in 1.6.18 and 1.7.3 Do Son
    Roundcube fixes a webmail RCE flaw and an SSRF filter bypass in versions 1.6.18 and 1.7.3. Update your mail server now. Related Posts: CVE-2026-19188: Haiwell HMI Gateway Flaw Lets Attackers Execute Arbitrary OS Commands With Root Privileges (CVSS 10.0) Linux AF_PACKET Race (03390aa): PoC Exploit Enables Local Privilege Escalation Citrix NetScaler Pre-Auth RCE CVE-2026-8452 Gets Public Exploit Code The post Roundcube Patches RCE and SSRF Flaws in 1.6.18 and 1.7.3 appeared first on Daily Cyber
     
  • ✇SpiderLabs Blog
  • The Infrastructure Relay: Inside Multi-Stage Phishing Redirection Chains Karla Agregado
    To stay ahead of evolving threats, LevelBlue utilizes a machine-learning-based URL scanner that constantly evaluates the digital landscape. We closely monitor VirusTotal for instances where LevelBlue acts as the sole detection layer — a crucial tactic for spotting new phishing campaigns early. In this blog, we will unpack several notable phishing campaigns discovered through this method.
     

The Infrastructure Relay: Inside Multi-Stage Phishing Redirection Chains

12 de Agosto de 2026, 10:42

To stay ahead of evolving threats, LevelBlue utilizes a machine-learning-based URL scanner that constantly evaluates the digital landscape. We closely monitor VirusTotal for instances where LevelBlue acts as the sole detection layer — a crucial tactic for spotting new phishing campaigns early. In this blog, we will unpack several notable phishing campaigns discovered through this method.

  • ✇Cybersecurity News
  • CVE-2026-66147: Unauthenticated Remote Code Execution Flaws Hit SonicWall GMS Do Son
    SonicWall GMS vulnerability CVE-2026-66147 (CVSS 9.4) enables unauthenticated remote code execution. Patch GMS to 9.5.2 without delay. Related Posts: Zero-Click File Drop Hits Xiaomi ShareMe: PoC Public CVE-2026-65640: WordPress 7.0.4 Fixes Remote Code Execution MariaDB Low-Privilege Remote Code Execution Chain: Full Details and PoC Exploit Code Publicly Disclosed The post CVE-2026-66147: Unauthenticated Remote Code Execution Flaws Hit SonicWall GMS appeared first on Daily CyberSecurity.
     

Apple Fixes Hide My Email Bug After Yearlong Delay

23 de Julho de 2026, 17:11

Apple patched a Hide My Email flaw that could expose real inbox addresses, after a researcher reportedly flagged the issue more than a year earlier.

The post Apple Fixes Hide My Email Bug After Yearlong Delay appeared first on TechRepublic.

Apple Sued Over Hide My Email Privacy Claims

17 de Julho de 2026, 11:19

Apple faces a proposed class action alleging a Hide My Email flaw could expose users’ real addresses despite the company’s privacy claims.

The post Apple Sued Over Hide My Email Privacy Claims appeared first on TechRepublic.

4 Best Email Security Solutions to Keep Employee Inboxes Safe

Compare leading and best email security solutions with AI threat detection, phishing defense, malware blocking, and DLP features for teams.
  • ✇Security Affairs
  • Government and Healthcare Are the Weakest Links in Global Email Security Pierluigi Paganini
    Government and healthcare sectors have weak email security. Many domains lack SPF, DMARC, DKIM, and MTA-STS, leaving them open to phishing attacks. Comparitech analyzed live DNS records for 5,849 domains across 13 sectors and scored each one out of 8 points based on four standard email authentication protocols: SPF, DMARC, DKIM, and MTA-STS. The results aren’t flattering. More than 8 percent of organizations had zero protection in place, and only 0.6 percent — 33 domains out of 5,849 — score
     

Government and Healthcare Are the Weakest Links in Global Email Security

3 de Julho de 2026, 05:01

Government and healthcare sectors have weak email security. Many domains lack SPF, DMARC, DKIM, and MTA-STS, leaving them open to phishing attacks.

Comparitech analyzed live DNS records for 5,849 domains across 13 sectors and scored each one out of 8 points based on four standard email authentication protocols: SPF, DMARC, DKIM, and MTA-STS. The results aren’t flattering. More than 8 percent of organizations had zero protection in place, and only 0.6 percent — 33 domains out of 5,849 — scored full marks. That’s 33 organizations out of nearly 6,000 doing everything right.

Government came last, with an average score of 2.73 out of 8.

“121 out of the 452 domains we scanned had zero protections in place (27%)–the highest of all sectors.” reads the report published by Comparitech. “No government domains scored full marks, but three did score 7.5 – Australia’s national science agency (CSIRO), the Mila – Quebec Artificial Intelligence Institute in Canada, and The Alan Turing Institute in the UK (also dedicated to data science and artificial intelligence).”

China’s government domains averaged just 0.9, with 65 percent having no protection at all. France wasn’t far behind at 1.4 average and 47 percent unprotected. The UK and US were the best performers in the sector, but even 17 percent of US government domains had zero protection — despite a Department of Homeland Security mandate requiring DMARC on all federal email domains.

Healthcare providers ranked second-worst at 3.43.

“85 out of the 438 domains we scanned had zero protections in place (19%) — the second highest of all sectors.” continues the report. “Four domains scored full points. Three of these were part of the UK’s NHS (NHS Blood and TransplantManchester University NHS Foundation Trust, and University Hospitals Birmingham NHS Foundation Trust), and one was the Dutch cancer specialist, Prinses Máxima Centrum.”

Chinese healthcare provider domains averaged 2.1, with 45 percent fully unprotected. The Netherlands was the outlier in healthcare, averaging 6.0 with zero unprotected domains — and four domains there scored perfect marks, including three NHS trusts in the UK and a Dutch cancer center.

Universities showed an interesting failure mode. Nearly 86 percent had a DMARC record in place, which sounds good. But 42 percent of those had left DMARC in monitoring-only mode, which means phishing emails pass straight through without being blocked or quarantined. Setting up DMARC and never enforcing it is roughly equivalent to installing a lock and leaving the key in it.

Technology companies led the field with an average score of 4.83, and only 2 percent of their domains had zero protection. Only two domains in the entire study scored perfect 8/8 across all sectors: microsoft.com and f5.com. On the country side,

“Asian countries/territories had the lowest average scores, with China (2.3), South Korea (2.84), Hong Kong (3.07), and Japan (3.53) ranking among the lowest. The European countries of France (3.77), Germany (3.8), and Spain (3.98) also scored poorly.” states Comparitech.”Among the highest-scoring countries were the Netherlands (5.51), Denmark (5.33), Norway (5.31), and Finland (5.19).”

The Nordic pattern isn’t accidental: GDPR creates pressure toward stronger data protection practices, and it shows in the scores.

MTA-STS, the protocol that enforces encrypted connections for email transfer, is almost universally ignored. Only 3 percent of all domains in the study had it in place. SPF was present on 90 percent of domains and DMARC on 81 percent, but having a record in place and enforcing it are different things: a DMARC policy set to p=none does nothing to stop a phishing email from landing in someone’s inbox.

“Our report highlights how each and every industry and country has room for improvement when it comes to email security. This is even the case within sectors and/or countries where email security is regulated to some degree.” concludes the report.

“Equally, certain sectors within specific countries face heavier regulation. For example, in the US, the Department of Homeland Security (DHS) mandates that DMARC should be in use on all government agency email domains. And, in the UK, the Government Digital Service (GDS) requires DMARC across governmental domains, and with p=reject (hard fail)”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Email Security)

  • ✇Security Boulevard
  • DKIM2 Explained: What’s Changing and What to Do Hagop K.
    Originally published at DKIM2 Explained: What’s Changing and What to Do by Hagop K.. Our team was at a deliverability summit where ... The post DKIM2 Explained: What’s Changing and What to Do appeared first on EasyDMARC. The post DKIM2 Explained: What’s Changing and What to Do appeared first on Security Boulevard.
     

Best of the Worst: Five Attacks That Looked Broken (and Worked)

25 de Abril de 2026, 08:38

I skipped last week's roundup. Holiday weekend, family stuff, the usual. So this is a two-week-ish view of what we've published in the Threat Intelligence series since Edition 03 dropped on April 13.

The post Best of the Worst: Five Attacks That Looked Broken (and Worked) appeared first on Security Boulevard.

  • ✇Security Boulevard
  • How to Tell if An Email is Fake: Complete Verification Guide Levon Vardumyan
    Originally published at How to Tell if An Email is Fake: Complete Verification Guide by Levon Vardumyan. A fake email is an email that appears ... The post How to Tell if An Email is Fake: Complete Verification Guide appeared first on EasyDMARC. The post How to Tell if An Email is Fake: Complete Verification Guide appeared first on Security Boulevard.
     

MXtoolbox Review: Features, User Experiences, Pros & Cons (2026)

14 de Abril de 2026, 07:22

Is MXToolbox worth it in 2026? Discover its features, limitations, user reviews, and how it compares to PowerDMARC for email security.

The post MXtoolbox Review: Features, User Experiences, Pros & Cons (2026) appeared first on Security Boulevard.

Sales Outreach Security: 5 Ways to Stop Your Sales Team from Looking Like Phishers

14 de Abril de 2026, 07:02

Is your sales team accidentally looking like phishers? Learn 5 proven ways to secure sales outreach emails and start landing in inboxes.

The post Sales Outreach Security: 5 Ways to Stop Your Sales Team from Looking Like Phishers appeared first on Security Boulevard.

Is Gmail Filtering Your Emails? Causes, Signs & Fixes

7 de Abril de 2026, 08:12

Find out why Gmail is filtering your emails, what triggers its spam filters, and how to fix it — including authentication, sender reputation, and content issues.

The post Is Gmail Filtering Your Emails? Causes, Signs & Fixes appeared first on Security Boulevard.

How to Send Secure Email in Gmail: Step-by-Step Guide

7 de Abril de 2026, 07:49

Learn how to send secure email in Gmail using Confidential Mode, S/MIME encryption, and best practices to protect sensitive messages in Google Workspace.

The post How to Send Secure Email in Gmail: Step-by-Step Guide appeared first on Security Boulevard.

Is Outlook Email Encryption HIPAA Compliant? A Complete Guide for 2026

5 de Março de 2026, 07:00

A practical guide to Outlook HIPAA compliance. Learn encryption requirements, configuration steps, and when to choose dedicated HIPAA email solutions.

The post Is Outlook Email Encryption HIPAA Compliant? A Complete Guide for 2026 appeared first on Security Boulevard.

❌
❌