home.social

#email-security — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #email-security, aggregated by home.social.

fetched live
  1. FYI: Apple keeps Hide My Email on icloud.com after community feedback: New Apple ID relay addresses shift to private.icloud.com late 2026, but old ones keep forwarding mail. Developers must update allowlists before the cutover. ppc.land/apple-keeps-hide-my-e #Apple #HideMyEmail #iCloud #Privacy #EmailSecurity

  2. 📰 ASCII Smuggling Phishing Attack Evades Filters with Unicode

    Microsoft uncovers a massive phishing campaign using 'ASCII smuggling' to evade filters. Attackers hid financial keywords with invisible Unicode characters, sending up to 2.37M emails per day. #Phishing #EmailSecurity #CyberAttack #Unicode

    🔗 cyber.netsecops.io/articles/as

  3. Microsoft Warns of Phishing Campaign Using Invisible Unicode to Evade Filters

    Microsoft uncovered a massive phishing campaign that sent a whopping 1-2.37 million messages daily on weekdays, peaking on February 26, 2026, and cleverly used invisible Unicode characters to slip past filters. The campaign's weekly rhythm was remarkably consistent, with a sharp drop in activity after May 15, 2026.

    osintsights.com/microsoft-warn

    #PhishingCampaign #InvisibleUnicode #Microsoft #EmergingThreats #EmailSecurity

  4. SVG Attachments Fuel Large-Scale Phishing with JavaScript Smuggling

    A massive phishing campaign, detected in over 5,500 organizations, used sneaky JavaScript smuggling tactics to evade native defenses, with a whopping 26,589 messages sent over just two months. The attackers cleverly exploited SVG attachments and voicemail lures to spread executable code.

    osintsights.com/svg-attachment

    #Phishing #JavascriptSmuggling #EmailSecurity #EmergingThreats #MalwareOperations

  5. 📰 Oculus Pathology Breach Exposes Patient Data via Email Hack

    Oculus Pathology discloses a data breach after employee email accounts were compromised in April 2026. The incident potentially exposed patient PII, PHI, SSNs, and medical diagnoses. #DataBreach #Healthcare #HIPAA #EmailSecurity

    🔗 cyber.netsecops.io/articles/oc

  6. Scammers are chaining forgotten CNAMEs to create fully authenticated phishing firehoses. Valid crypto means nothing when the pipes are rotten.

    andreklein.net/dns-debt-how-ph

    #InfoSec #CyberSecurity #DNS #EmailSecurity

  7. pmg-userprefs-sync is now public

    📬 We have published pmg-userprefs-sync:
    code.awit.at/D3/pmg-userprefs-

    This small tool keeps per-user welcome/block lists from quarantine digests in sync across two standalone Proxmox Mail Gateways. A recipient’s decision therefore applies regardless of which equal-priority MX receives the next message.

    The design is deliberately restrictive:

    - Read peer data only through the PMG API with an Auditor role
    - Write changes only locally via pmgsh
    - Add-only: no automatic removals and no data loss
    - No PMG cluster, no pmgcm, and no SSH between gateways
    - Dry-run is the safe default; the systemd timer is optional

    It deliberately does not synchronise filter rules, transports, TLS policies, spam scores, or quarantine contents. Those are separate concerns with different risks.

    Tested with PMG 9.1.2 across two production gateways. 🔧

    #Proxmox #ProxmoxMailGateway #PMG #Mailserver #SelfHosting #OpenSource #Linux #Sysadmin #DevOps #EmailSecurity #AGPL

  8. pmg-userprefs-sync ist jetzt öffentlich

    📬 Wir haben pmg-userprefs-sync veröffentlicht:
    code.awit.at/D3/pmg-userprefs-

    Das kleine Tool hält auf zwei unabhängigen Proxmox Mail Gateways die persönlichen Welcome-/Blocklisten aus den Quarantäne-Digests synchron. So wirkt die Entscheidung eines Empfängers unabhängig davon, über welchen gleichpriorisierten MX die nächste Mail ankommt.

    Der Ansatz ist bewusst restriktiv:

    - Peer-Daten nur lesend über die PMG-API mit Auditor-Rolle
    - Änderungen ausschließlich lokal über pmgsh
    - add-only: keine automatischen Löschungen, kein Datenverlust
    - kein PMG-Cluster, kein pmgcm, kein SSH zwischen den Gateways
    - Dry-run als sicherer Standard, systemd-Timer optional

    Nicht synchronisiert werden Filterregeln, Transports, TLS-Policies, Spam-Scores oder Quarantäne-Inhalte. Das sind bewusst getrennte Themen mit anderen Risiken.

    Getestet mit PMG 9.1.2 auf zwei produktiven Gateways. 🔧

    #Proxmox #ProxmoxMailGateway #PMG #Mailserver #SelfHosting #OpenSource #Linux #Sysadmin #DevOps #EmailSecurity #AGPL

  9. Sendmail sits in the path of every email transaction your organization sends or receives. It logs auth attempts, TLS negotiations, relay IPs, forged hostnames, and rejections.

    Most teams treat that as noise. It's early-warning threat telemetry.

    The Sendmail Content Pack for Graylog parses those logs into GIM-mapped events and a six-tab Illuminate dashboard, automatically.

    graylog.org/post/sendmail-data

    #SIEM #ThreatHunting #EmailSecurity

  10. Oh, look! Another thrilling tale about #DMARC, saving us from emails we never wanted and threats we don’t understand 🙄. But don't worry—this article manages to make email security as riveting as watching paint dry while they shamelessly plug their product 🤦‍♂️. Spoiler: It won’t protect you from bad writing! 📧🔒
    senderledger.com/articles/what #EmailSecurity #CyberThreats #ProductPlug #EmailSafety #HackerNews #ngated

  11. Far to the north in Norway, we protect your email from viruses, harmful attachments, spam, and malicious scripts. 🇳🇴

    👉 runbox.com/features/privacy-se

    #Emailsecurity #Security #Privacy #Runbox #Norway #European #Email #Degoogle

  12. On what planet would people not bother setting a simple switch to tell email servers to discard email claiming to be from their domains but aren't? You know to protect unsuspecting victims, protect the reputation of their domains, and prevent their domains from being shut down permanently for spam?

    Apparently Earth.

    People who leave the default option as it being OK to deliver spoofed email from their domain even if the email is screaming that it's a spoof, well, you know, deserve to lose their domain names, IMHO. What do you think?

    ciphercue.com/blog/dmarc-enfor

    #CyberSecurity #DMARC #SPF #DKIM #EmailSecurity

  13. 🚨 BREAKING NEWS: The internet is shocked! 🚨 68.4% of companies still can't handle basic email security a mere 11 YEARS after DMARC's debut! 🎉 Let's all pretend to be surprised while they fumble with their DNS records like it's rocket science! 😂
    ciphercue.com/blog/dmarc-enfor #internetsecurity #emailsecurity #DMARC #cybersecurity #dnsrecords #shockingnews #HackerNews #ngated