Daily DMARC News
  • Home
  • Posts
  • Excello Mail ↗
  • EN
  • ES
  • PT

All Posts

Every post we’ve published — newest first.

News on this site is aggregated and summarized automatically from public industry sources. Occasional inaccuracies are possible and always unintentional — if you spot one, we’ll gladly correct or remove it. Report an issue.

  • August 19, 2026 5 min read

    One Split Write, One Missing Dot: The .NET Bug That Lets a Contact Form Smuggle a Second Email

    Most of the email injection bugs covered here start in a narrow corner of the internet: one WordPress plugin, one Java library. CVE-2026-50659 does not. It sits inside System.Net.Mail, the SMTP client built into every …

  • August 18, 2026 5 min read

    3,000 Fake Recruiter Windows and a Backend Operator Choosing Your MFA Screen in Real Time

    A fake job offer is one of the oldest lures in phishing. What CTM360 documented this month in a campaign it calls RecruitTrap is not old at all: a fake browser window convincing enough to fool the browser itself, wired …

  • August 17, 2026 6 min read

    A Phishing Email Charged You $459.90 for Windows Defender. Microsoft Sent It, and DMARC Passed.

    Azure Monitor is a legitimate Microsoft service that watches your cloud resources and emails you when something needs attention. That is exactly why threat actors have spent the past several months turning it into a …

  • August 16, 2026 5 min read

    A Phishing Link Passed Through Five Trusted Security Vendors Before It Ever Reached the Malicious Page. DMARC Never Saw a Single Hop.

    Most secure email gateways rewrite the links inside a message before it ever reaches an inbox, replacing the original URL with a vendor-branded one that routes through the vendor’s scanning infrastructure first. It …

  • August 15, 2026 4 min read

    It Failed DMARC. Microsoft 365 Delivered It to the Inbox Anyway, Because of a Tag Called SCL:-1.

    Publishing a DMARC record with p=reject is supposed to be the finish line. It tells every receiving mail server, in writing, to throw away anything claiming to be from your domain that cannot prove it. Security …

  • August 14, 2026 5 min read

    LogoKit Now Screenshots Your Real Login Page and Rebuilds It Live. DMARC's Job Was Already Finished By Then.

    Barracuda published research on July 29, 2026, tracking the evolution of LogoKit, a phishing kit that has circulated in criminal markets since 2018. What used to be a simple template that swapped in a static company logo …

  • August 13, 2026 5 min read

    One Compromised Inbox Plus Microsoft Copilot Equaled a $247,500 Wire Fraud. DMARC Was Never in the Room.

    Barracuda’s Red Team published research on August 4, 2026, ahead of Black Hat USA 2026, that should reframe how security teams think about the AI assistants now built into every major mailbox. Their controlled …

  • August 12, 2026 5 min read

    9,394 Phishing Emails Came Straight From Google's Own Servers. DMARC Passed on Every One.

    Check Point’s Harmony Email research team disclosed a phishing campaign built on a premise that should worry anyone who treats authentication as proof of safety: the messages were not spoofed at all. They were sent …

  • August 11, 2026 6 min read

    A Real Invoice Email From a Real Compromised Mailbox Is Now How Banking Malware Gets Installed. DMARC Passes Every Time.

    Gen Digital, the company behind Norton and Avast, published its H1 2026 Threat Report this month, and buried inside it is an attack chain that deserves more attention than a single line item. Researchers documented a …

  • August 10, 2026 5 min read

    CSS Alone Can Now Steal a Password Inside Gmail, Outlook, and Yahoo Mail. No JavaScript, No Link, and DMARC Never Sees It.

    At Black Hat USA 2026, PortSwigger researcher Gareth Heyes presented a talk called “CSS: the bomb inside your inbox,” and the finding underneath the title is a genuinely uncomfortable one for anyone who …

  • August 9, 2026 6 min read

    43% of BEC Emails Now Just Ask for Your Phone Number. Once You Reply, DMARC Is Out of the Conversation.

    LevelBlue’s SpiderLabs threat research team, the group formerly under AT&T Cybersecurity, closed out its review of 2025 business email compromise activity with a number that should reframe how most security …

  • August 8, 2026 5 min read

    Payroll Pirates Now Route Phishing Through Google Meet and AWS S3. The Session ID Outlives the IP Address.

    Arctic Wolf researchers are tracking a widespread, email-driven phishing campaign that shares clear tactical overlap with Storm-2755, the cluster Microsoft first named “Payroll Pirate” in April after it …

  • ««
  • «
  • 1
  • 2
  • 3
  • 4
  • 5
  • »
  • »»
Daily DMARC News

Daily news, analysis, and guidance on DMARC and email security.

Explore

  • Home
  • All posts
  • RSS feed

From the team

  • Excello Mail ↗
  • About
  • Contact
© 2026 Daily DMARC News. All rights reserved. From the team at Excello Mail.