#email-security — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #email-security, aggregated by home.social.
-
Microsoft uncovered an ASCII smuggling phishing evasion campaign hitting email inboxes. Learn how attackers weaponize invisible Unicode tags.
#ASCIISmuggling #Phishing #EmailSecurity #Cybersecurity #Microsoft
-
A Microsoft 365 RejectDirectSend bypass lets attackers spoof internal emails. Learn how this RejectDirectSend bypass works and how to protect your tenant.
#Microsoft365 #Phishing #EmailSecurity #ExchangeOnline #Cybersecurity
https://securityonline.info/rejectdirectsend-bypass/?utm_source=mastodon&utm_medium=jetpack_social
-
FYI: Apple keeps Hide My Email on icloud.com after community feedback: New Apple ID relay addresses shift to private.icloud.com late 2026, but old ones keep forwarding mail. Developers must update allowlists before the cutover. https://ppc.land/apple-keeps-hide-my-email-on-icloud-com-after-community-feedback/ #Apple #HideMyEmail #iCloud #Privacy #EmailSecurity
-
Exchange Online blocking of outdated Exchange 2016 and 2019 servers begins in September 2026, requiring the October 2025 update baseline.
#Exchange #ExchangeOnline #Microsoft365 #EmailSecurity #ExchangeServer #HybridMail #ESU
-
📰 ASCII Smuggling Phishing Attack Evades Filters with Unicode
Microsoft uncovers a massive phishing campaign using 'ASCII smuggling' to evade filters. Attackers hid financial keywords with invisible Unicode characters, sending up to 2.37M emails per day. #Phishing #EmailSecurity #CyberAttack #Unicode
-
The Roundcube security update fixes 12 webmail flaws, including a zero-click stored XSS and an SSRF bypass. Update to 1.6.19 or 1.7.4 now.
#Roundcube #Webmail #XSS #SSRF #EmailSecurity #StoredXSS #PatchNow #Infosec
-
Microsoft Warns of Phishing Campaign Using Invisible Unicode to Evade Filters
Microsoft uncovered a massive phishing campaign that sent a whopping 1-2.37 million messages daily on weekdays, peaking on February 26, 2026, and cleverly used invisible Unicode characters to slip past filters. The campaign's weekly rhythm was remarkably consistent, with a sharp drop in activity after May 15, 2026.
#PhishingCampaign #InvisibleUnicode #Microsoft #EmergingThreats #EmailSecurity
-
SVG Attachments Fuel Large-Scale Phishing with JavaScript Smuggling
A massive phishing campaign, detected in over 5,500 organizations, used sneaky JavaScript smuggling tactics to evade native defenses, with a whopping 26,589 messages sent over just two months. The attackers cleverly exploited SVG attachments and voicemail lures to spread executable code.
#Phishing #JavascriptSmuggling #EmailSecurity #EmergingThreats #MalwareOperations
-
5 Levels of Email Security Explained
-
Google launches the Gmail Verified Sender Program, allowing political campaigns to bypass spam filters ahead of the 2026 US Mid-term Elections.
-
📰 Oculus Pathology Breach Exposes Patient Data via Email Hack
Oculus Pathology discloses a data breach after employee email accounts were compromised in April 2026. The incident potentially exposed patient PII, PHI, SSNs, and medical diagnoses. #DataBreach #Healthcare #HIPAA #EmailSecurity
-
Scammers are chaining forgotten CNAMEs to create fully authenticated phishing firehoses. Valid crypto means nothing when the pipes are rotten.
https://andreklein.net/dns-debt-how-phishing-campaigns-pass-dkim-without-hacking-anything/
-
pmg-userprefs-sync is now public
📬 We have published pmg-userprefs-sync:
https://code.awit.at/D3/pmg-userprefs-syncThis small tool keeps per-user welcome/block lists from quarantine digests in sync across two standalone Proxmox Mail Gateways. A recipient’s decision therefore applies regardless of which equal-priority MX receives the next message.
The design is deliberately restrictive:
- Read peer data only through the PMG API with an Auditor role
- Write changes only locally via pmgsh
- Add-only: no automatic removals and no data loss
- No PMG cluster, no pmgcm, and no SSH between gateways
- Dry-run is the safe default; the systemd timer is optionalIt deliberately does not synchronise filter rules, transports, TLS policies, spam scores, or quarantine contents. Those are separate concerns with different risks.
Tested with PMG 9.1.2 across two production gateways. 🔧
#Proxmox #ProxmoxMailGateway #PMG #Mailserver #SelfHosting #OpenSource #Linux #Sysadmin #DevOps #EmailSecurity #AGPL
-
pmg-userprefs-sync ist jetzt öffentlich
📬 Wir haben pmg-userprefs-sync veröffentlicht:
https://code.awit.at/D3/pmg-userprefs-syncDas kleine Tool hält auf zwei unabhängigen Proxmox Mail Gateways die persönlichen Welcome-/Blocklisten aus den Quarantäne-Digests synchron. So wirkt die Entscheidung eines Empfängers unabhängig davon, über welchen gleichpriorisierten MX die nächste Mail ankommt.
Der Ansatz ist bewusst restriktiv:
- Peer-Daten nur lesend über die PMG-API mit Auditor-Rolle
- Änderungen ausschließlich lokal über pmgsh
- add-only: keine automatischen Löschungen, kein Datenverlust
- kein PMG-Cluster, kein pmgcm, kein SSH zwischen den Gateways
- Dry-run als sicherer Standard, systemd-Timer optionalNicht synchronisiert werden Filterregeln, Transports, TLS-Policies, Spam-Scores oder Quarantäne-Inhalte. Das sind bewusst getrennte Themen mit anderen Risiken.
Getestet mit PMG 9.1.2 auf zwei produktiven Gateways. 🔧
#Proxmox #ProxmoxMailGateway #PMG #Mailserver #SelfHosting #OpenSource #Linux #Sysadmin #DevOps #EmailSecurity #AGPL
-
Sendmail sits in the path of every email transaction your organization sends or receives. It logs auth attempts, TLS negotiations, relay IPs, forged hostnames, and rejections.
Most teams treat that as noise. It's early-warning threat telemetry.
The Sendmail Content Pack for Graylog parses those logs into GIM-mapped events and a six-tab Illuminate dashboard, automatically.
-
Oh, look! Another thrilling tale about #DMARC, saving us from emails we never wanted and threats we don’t understand 🙄. But don't worry—this article manages to make email security as riveting as watching paint dry while they shamelessly plug their product 🤦♂️. Spoiler: It won’t protect you from bad writing! 📧🔒
https://senderledger.com/articles/what-dmarc-actually-protects-you-from #EmailSecurity #CyberThreats #ProductPlug #EmailSafety #HackerNews #ngated -
What DMARC Protects You From, and What It Does Not
https://senderledger.com/articles/what-dmarc-actually-protects-you-from
Comments: https://news.ycombinator.com/item?id=49153361
#HackerNews #DMARC #EmailSecurity #CyberThreats #EmailAuthentication #InternetSafety
-
Far to the north in Norway, we protect your email from viruses, harmful attachments, spam, and malicious scripts. 🇳🇴
👉 https://runbox.com/features/privacy-security/
#Emailsecurity #Security #Privacy #Runbox #Norway #European #Email #Degoogle
-
On what planet would people not bother setting a simple switch to tell email servers to discard email claiming to be from their domains but aren't? You know to protect unsuspecting victims, protect the reputation of their domains, and prevent their domains from being shut down permanently for spam?
Apparently Earth.
People who leave the default option as it being OK to deliver spoofed email from their domain even if the email is screaming that it's a spoof, well, you know, deserve to lose their domain names, IMHO. What do you think?
https://ciphercue.com/blog/dmarc-enforcement-gap-rua-fragmentation-2026
-
🚨 BREAKING NEWS: The internet is shocked! 🚨 68.4% of companies still can't handle basic email security a mere 11 YEARS after DMARC's debut! 🎉 Let's all pretend to be surprised while they fumble with their DNS records like it's rocket science! 😂
https://ciphercue.com/blog/dmarc-enforcement-gap-rua-fragmentation-2026 #internetsecurity #emailsecurity #DMARC #cybersecurity #dnsrecords #shockingnews #HackerNews #ngated -
DMARC Has Been Public Since 2012. 68.4% of Domains Still Don't Enforce It
https://ciphercue.com/blog/dmarc-enforcement-gap-rua-fragmentation-2026
Comments: https://news.ycombinator.com/item?id=49081783
#HackerNews #DMARC #cybersecurity #emailsecurity #domainprotection #enforcement