Quantum Readiness Day on September 24 is a useful reminder that the security work we do today is not only about preventing breaches tomorrow. It is about protecting data and digital trust for years to come.
![]()
Quantum Readiness Day on September 24 is a useful reminder that the security work we do today is not only about preventing breaches tomorrow. It is about protecting data and digital trust for years to come.
![]()
Researchers at Microsoft are tracking an AI-assisted phishing campaign that sent over a million emails attempting to conduct payment diversion scams.
![]()
A massive phishing campaign is using invisible Unicode tag characters to evade security filters, according to researchers at Microsoft. This technique, known as “ASCII smuggling,” has grown popular over the past year for launching AI prompt injection attacks, but the same tactic can hide suspicious text in emails.
![]()
AI tools are drastically improving the speed of the reconnaissance stage of targeted social engineering attacks, according to researchers at ESET. Attackers can use these tools to trawl the internet for publicly available information about potential victims, and incorporate this information into personalized spear phishing attacks.
![]()
Attackers have used a new phishing platform called “BigBear 2.0” to target hundreds of organizations across more than forty countries, according to researchers at CloudSEK. In about 10% of cases, the phishing attacks were able to bypass multifactor authentication.
![]()
Researchers at Microsoft are tracking a social engineering campaign that uses passkey-themed lures to trick users into granting persistent access to their accounts and online work environments.
![]()
Threat actors are using phishing emails with blank SMTP sender fields to bypass Microsoft 365 security filters, according to researchers at ReliaQuest.
Microsoft 365 Exchange Online uses a feature called “RejectDirectSend” to block unauthenticated Direct Send emails from an organization’s trusted domain. If an attacker omits the domain field from these emails, however, RejectDirectSend will no longer block the messages. Attackers can therefore exploit this technique to impersonate internal users.
![]()