Daily DMARC News
  • Home
  • Posts
  • Excello Mail ↗
  • EN
  • ES
  • PT

All Posts

Every post we’ve published — newest first.

News on this site is aggregated and summarized automatically from public industry sources. Occasional inaccuracies are possible and always unintentional — if you spot one, we’ll gladly correct or remove it. Report an issue.

  • September 12, 2026 6 min read

    One Login Flaw at an Email Marketing Platform Reached 138 Companies. The Phishing It Sent Passed DMARC Because It Was Genuinely Them.

    On September 9, 2026, roughly 347,000 people who had signed up for Trezor’s newsletter received an email warning them that a factory defect in the STM32 microcontroller used in their hardware wallet made their …

  • September 11, 2026 5 min read

    PREY-0058 Breaks Into Microsoft 365 With a Phone Call. DMARC Was Never Part of the Path.

    Every campaign in this series so far has started with a message landing in an inbox. PREY-0058 does not. Arctic Wolf is tracking a widespread cluster of intrusions that begins with a phone call or a text message, and by …

  • September 10, 2026 5 min read

    BigBear 2.0 Beat MFA at 258 Companies. Its Follow-Up Emails Passed DMARC Because They Were Genuinely From the Victim.

    Most phishing kits still fail the moment a target has multi-factor authentication turned on. BigBear 2.0 does not. Researchers on CloudSEK’s TRIAD team found the operator’s control panel and got into it …

  • September 9, 2026 4 min read

    The Phishing Email Was Genuinely From Adobe. SPF, DKIM, and DMARC All Passed, and That Was the Problem.

    Most of the campaigns we cover pass DMARC by routing around it entirely, borrowing a compromised mailbox, an OAuth token, or a reputable ESP’s sending pool. Email security vendor IRONSCALES documented something …

  • September 8, 2026 5 min read

    26,589 Fake Voicemails Failed DMARC. A Legitimate Email Platform's Reputation Delivered Them Anyway.

    Between June 1 and August 4, email security vendor INKY, now part of Kaseya, tracked a phishing campaign that ran in waves, mostly stopping on weekends, and landed 26,589 messages in 5,527 organizations. The largest …

  • September 7, 2026 6 min read

    A Fake Canadian Tax Slip Grew Into a 46-Country Campaign That Installs Real Remote Access Software

    Research from ANY.RUN, published August 25, started with something narrow: a wave of fake Canada Revenue Agency T4 tax slips landing in Canadian inboxes. By the time the researchers finished tracing the infrastructure …

  • September 6, 2026 6 min read

    The FBI Seized Their Servers and $100,000 in June. By September, the Same Phishing Kit Had 700 New Domains.

    In June, Google sued the operators behind Outsider, a phishing-as-a-service kit tied to a threat actor known as ChenLun, and the FBI’s Cyber Division opened Operation Ghost Hook the very next day to dismantle it. …

  • September 5, 2026 5 min read

    An AI Jailbreak Trick Just Crossed Over to Phishing. It Splits the Word 'Funding' With a Space No One Can See, 2.37 Million Times a Day

    ASCII smuggling started out as a problem for AI systems: hide invisible Unicode characters inside a block of text, and a large language model reading that text can be steered by instructions no human reviewer would ever …

  • September 4, 2026 5 min read

    The Same Link Installs Android Studio for Everyone Except Victims in Brazil

    Most phishing analysis assumes a link either leads to something bad or it does not, and that whoever tests it will see the same thing an intended victim sees. Research the SANS Internet Storm Center published on …

  • September 3, 2026 4 min read

    457 Endpoints Enrolled in an Attacker's Own Software Deployment. The Installer Was Genuinely Signed, and DMARC Had Nothing Left to Check.

    Most of the posts in this series look at what a phishing email does while it is still an email: what domain it claims to be from, what link it carries, what attachment it hides behind. Research Huntress published on …

  • September 2, 2026 5 min read

    The Emails KnowBe4 Just Built an AI to Catch Have No Link, No Attachment, and a Perfectly Clean DMARC Pass.

    Most email security products still describe themselves by what they scan: links, attachments, headers. On August 31, KnowBe4 announced Defend for Google Workspace, its first extension of behavioral email security to …

  • September 1, 2026 5 min read

    The Phishing Email Had No Link. An Attachment Built the Fake Microsoft Login Page Inside the Browser, and DMARC Had Nothing Left to Check.

    Most phishing emails still rely on a link. A recipient clicks it, lands on a hosted page somewhere, and that page’s domain is at least something a security team can flag or block. New research from threat …

  • ««
  • «
  • 1
  • 2
  • 3
  • 4
  • 5
  • »
  • »»
Daily DMARC News

Daily news, analysis, and guidance on DMARC and email security.

Explore

  • Home
  • All posts
  • RSS feed

From the team

  • Excello Mail ↗
  • About
  • Contact
© 2026 Daily DMARC News. All rights reserved. From the team at Excello Mail.