home.social

#email — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #email, aggregated by home.social.

fetched live
  1. "Have questions about your solar system?" was momentarily a very exciting email subject to have received. I had an entire internal monologue where I speculated that maybe some famous astronomer was reaching out to assuage my deepest fears and insecurities about space and galaxies. Imagine my disappointment when I realized the communiqué was from my rooftop solar panel installation vendor just wanting to ping me on kilowatt hours or something. #solar #systems #questions #email #subjects #hustling

  2. This is why I never cared, at all, about encrypted email. Stop Using Encrypted Email latacora.com/blog/2020/02/19/s #Email

  3. ☀️ Un été léger avec Mailo : en voyage, connectez-vous à Mailo en toute sécurité !

    Depuis un appareil ou un réseau inhabituel, quelques précautions simples permettent de protéger votre compte et vos données. Découvrez nos conseils pour voyager l’esprit tranquille.

    blog.mailo.com/blog/un-ete-leg

    #Mailo #Vacances #Cybersécurité #ViePrivée #SécuritéNumérique #Email

  4. Mozilla Thunderbird 154 è disponibile con una lunga serie di miglioramenti, nuove integrazioni e correzioni per email, calendario e account Microsoft 365. #Thunderbird #Mozilla #Linux #OpenSource #Email linuxeasy.org/mozilla-thunderb

  5. Beware of Phishing Emails Disguised as Quote Confirmation Requests (PhantomStealer)

    Pulse ID: 6a86848c1231bc986eb5ecd8
    Pulse Link: otx.alienvault.com/pulse/6a868
    Pulse Author: Tr1sa111
    Created: 2026-08-20 04:37:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Email #InfoSec #OTX #OpenThreatExchange #Phishing #bot #Tr1sa111

  6. Mailove is fresh as lemon (if you download v3.1, you will get update notifications to keep it fresh with the latest bug fixes and features):
    github.com/nekromoff/mailove/r

  7. The good thing about being back in the office and in front of my laptop all day is Inbox Zero can be maintained in a much more constant state.

    Did my semi-annual purge and ‘unsubscribe’ from spam as well. With not too many faculty back yet, my email is currently feeling both slim *and* calm.

    How many of the folks reading this are Inbox Zero People (ie. heavy email filterers)

    #Work #Email #Spam #InboxZero

  8. Little UI / UX trick for the new update indicator for Mailove - it shrinks into a lemon emoji, so it does not bother you for too long:

  9. And probably coming to the UK in due course.

    “Google created a special delivery channel for political campaigns at the expense of its users’ control over their own inboxes.”

    But that’s the problem: they aren’t users’ own inboxes. They are Gmail’s inboxes. *All your email are belong to us.*

    proton.me/blog/gmail-political

    #Spam #Privacy #Email #Gmail

  10. Good news about these CSS attacks / exfiltration attacks on webmails and email clients? Mailove is fully secure with remote content off (=by default)!

    Now based on these news, I've added also fix in viewersecurity.cpp that narrows the opt-in to images only. Inline <style>, style attributes, and cid:/data: fonts are untouched.

    github.com/nekromoff/mailove

  11. Beware of Phishing Emails Disguised as Quote Confirmation Requests (PhantomStealer)

    A phishing campaign has been identified where attackers impersonate sales staff from specific overseas companies, requesting quotation modifications and product version confirmations. The email contains a malicious GZ compressed file that, when extracted, delivers an injector-type executable. This injector employs multiple UAC bypass techniques including SSPI-based authentication and CMSTPLUA COM exploitation to gain elevated privileges. It then performs BYOVD attacks using the vulnerable DCRCVDrv.sys driver to terminate security products through kernel-level access. Following security product neutralization, the injector uses process hollowing to inject PhantomStealer into the legitimate AddInProcess32.exe process. PhantomStealer then executes comprehensive information theft including keylogging, screen capture, browser credentials, cryptocurrency wallet data, and clipboard manipulation to replace wallet addresses with attacker-controlled ones.

    Pulse ID: 6a855b37f82f7d0075b2f111
    Pulse Link: otx.alienvault.com/pulse/6a855
    Pulse Author: AlienVault
    Created: 2026-08-19 07:28:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #CyberSecurity #Email #InfoSec #InformationTheft #LUA #OTX #OpenThreatExchange #Phishing #Troll #bot #cryptocurrency #AlienVault

  12. Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US

    Mirage2FA is an active phishing-as-a-service toolkit built to steal Microsoft 365 credentials and authenticated sessions through Adversary-in-the-Middle attacks. Analysis shows 63.7% of identified victims are in the US, with Technology, Manufacturing, and Education among the most targeted industries. The operation generated thousands of compromise events between 2024 and 2026, including stolen session cookies, passwords, and SSO access. Once a Microsoft 365 session is hijacked, attackers gain access to corporate email, sensitive data, and trusted business accounts. The toolkit uses browser-based delivery through .htm, .xhtml, and .svg stagers, QR codes, JavaScript obfuscation, and WebSocket-based AiTM activity. Of 9,426 unique targeted email addresses, 4,532 were potentially compromised, representing approximately 48% success rate.

    Pulse ID: 6a84c514863d37cbadb72833
    Pulse Link: otx.alienvault.com/pulse/6a84c
    Pulse Author: AlienVault
    Created: 2026-08-18 20:48:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #2FA #AdversaryInTheMiddle #AitM #Browser #Cookies #CyberSecurity #Education #Email #HTML #InfoSec #Java #JavaScript #Manufacturing #Microsoft #OTX #OpenThreatExchange #Password #Passwords #Phishing #RAT #Rust #SVG #Word #bot #AlienVault

  13. New York Times: Google Just Made It Easier for Campaigns to Send You Fund-Raising Emails. This link goes to a gift article. “Google quietly rolled out a new program on Monday that will allow candidates, political parties and political action committees to more easily bypass Gmail’s spam filter and send fund-raising appeals to the inboxes of the company’s many millions of email users.”

    https://rbfirehose.com/2026/08/19/new-york-times-google-just-made-it-easier-for-campaigns-to-send-you-fund-raising-emails/
  14. Beware of Phishing Emails Disguised as Transaction Receipts

    Pulse ID: 6a85364753aa39234e8bbbfa
    Pulse Link: otx.alienvault.com/pulse/6a853
    Pulse Author: Tr1sa111
    Created: 2026-08-19 04:51:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Email #InfoSec #OTX #OpenThreatExchange #Phishing #bot #Tr1sa111

  15. Email client for AmigaOS 3.2: AmiMAIL 1.0

    Andreas “Andiweli” Stürmer has released AmiMAIL 1.0, a new native IMAP/SMTP email client for AmigaOS 3.2. The program uses the ReAction interface and AmiSSL for secured connections and is designed for standard email providers with IMAP/SMTP access.

    amiga-news.de/en/news/AN-2026-

  16. 🚀 New #release · Bitwarden v2026.8.0

    What's Changed
    Feature Development
    • [PM-38923] feat: Add v2 UpdateOrganizationUser command with role-escalation validation by @jrmccannon in #7919
    • [PM-38926] feat: Add admin change member email to v2 UpdateOrganizationUser command by @jrmccannon in #7964
    • [PM-36011] feat: add member email cha…

    Details, install & alternatives → selfhost.directory/project/bit

    #docker #bitwarden #notifications #email #opensource

  17. Signed Overwolf Binary Sideloads ValleyRAT Malware in India

    A phishing campaign targets Indian organizations by impersonating the Indian Income Tax Department. Victims receive emails containing links to spoofed notice pages that download ZIP archives. These archives include a legitimately signed Overwolf executable and two hidden files: a malicious DLL and an encrypted binary. When executed, the signed binary side-loads the malicious DLL through DLL hijacking. The DLL is UPX-packed and modified with Astral-PE, and decrypts the binary file containing ValleyRAT. The payload uses modified RC4 encryption with a 115-byte key and deploys entirely in memory. Once active, ValleyRAT establishes persistence through scheduled tasks masquerading as OneDrive entries, marks dropped files as hidden and system files, and performs process hollowing into svchost.exe to evade detection before connecting to command and control infrastructure.

    Pulse ID: 6a8478fe441f9c15e06ee4cc
    Pulse Link: otx.alienvault.com/pulse/6a847
    Pulse Author: AlienVault
    Created: 2026-08-18 15:23:42

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #EDR #Email #Encryption #India #InfoSec #Malware #OTX #OpenThreatExchange #Phishing #RAT #ZIP #bot #AlienVault

  18. Mailove v3.0 - Tested & proven & offline & online
    The fast, friendly KDE-first email client

    github.com/nekromoff/mailove

    Huge overhaul of many features, mostly focused on making it work fully offline. Spotty signal? No worries, you can write your emails and Mailove will send them once online. Lots of new stuff like Undo send, even working around upstream KMime bugs (!) to achieve DKIM fidelity!

  19. Old good time? 🤔

    «Finger Protocol Malware — Python RAT via a 1970s:
    The finger protocol is older than the web, disabled on every server that matters, and still a working malware delivery channel on a default Windows install. Here it planted a Python RAT that was alerting the whole time. One genuine compromise, drowned in thousands of benign look-alikes, invisible until something cut through the noise»

    📧 artemissecurity.com/attack-sto

    #python #spam #email #malware #finger #protocol #old #web #windows

  20. Just got the beta invitation to Thunderbird's new email service. Not too bad price wise, but I'm a little curious if they will introduce a lower tier plan as right now it is more than 1 person would need for personal use I suspect. For the cost, you can consider Proton's Mail Plus or Unlimited.

    #technology #email #tech

  21. Beware of Phishing Emails Disguised as Transaction Receipts

    A sophisticated phishing campaign has been identified where attackers impersonate employees of a US company, sending emails that claim to contain transaction receipts. Recipients are urged to verify fund deposits by opening an attached PDF file. The malicious PDF displays a fake Adobe Flash Player update prompt, which when clicked, downloads a VBS script. This script executes with administrator privileges, displays a decoy payment receipt document, and silently installs ScreenConnect remote management software via an MSI package. The installation establishes persistent remote access to the compromised system, enabling attackers to execute commands, transfer files, and deploy additional payloads using legitimate administrative tools in a Living-off-the-Land attack technique.

    Pulse ID: 6a8431e74688d3e47ef55014
    Pulse Link: otx.alienvault.com/pulse/6a843
    Pulse Author: AlienVault
    Created: 2026-08-18 10:20:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Adobe #CyberSecurity #Email #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RAT #ScreenConnect #VBS #bot #AlienVault

  22. Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline

    Researchers identified an exposed web directory on infrastructure supporting a cryptocurrency fraud operation tracked as Operation ASTERIX. The server contained phone-number datasets, account-validation tools, phishing panels, voice-dialing scripts, and fake wallet applications for Ledger, Trezor, and Exodus. The operator validated approximately 885,000 phone numbers against cryptocurrency exchange accounts, achieving a 13.6% hit rate on German numbers. Victims received coordinated phishing emails and vishing calls referencing fake support cases before being directed to counterfeit wallet applications designed to steal recovery phrases via Telegram exfiltration. Notable findings include extensive use of AI coding assistants throughout development, including GitHub Copilot and Claude Code. When one AI model resisted malicious requests, the operator switched providers and attempted to bypass safety controls using a structured jailbreak prompt targeting the model's reasoning patterns and safety mechanisms.

    Pulse ID: 6a840692bd27524cbf560e2d
    Pulse Link: otx.alienvault.com/pulse/6a840
    Pulse Author: AlienVault
    Created: 2026-08-18 07:15:30

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Edge #Email #GitHub #InfoSec #NATO #OTX #OpenThreatExchange #Phishing #RAT #SMS #Telegram #bot #cryptocurrency #AlienVault