Issue #014June 8, 2026
VP of Marketing, Rebecca WarrenRebecca Warren

What's happening in email security: June 1 – June 7, 2026

No breach dominated this week and no vendor shipped an emergency patch. What we got instead was a clear picture of where phishing actually is in mid-2026, and it's not the fake login page you're picturing. Attackers spent the week delivering JavaScript inside image files, skipping links entirely for phone numbers, and swapping credential-harvesting pages for malware that just takes the session cookie. The login prompt is optional now.

SVG attachments that are all script, no picture

SANS ISC caught a wave of phishing emails carrying SVG attachments that contain zero graphics, just embedded JavaScript that redirects the browser to a phishing page. There's no URL in the email body for a gateway to flag, and SVG files open in the default browser on Windows. The payload is Base64-encoded and XOR'd, and the script declares itself as `application/ecmascript` instead of a standard JavaScript type to slip past signature-based tools. The redirect even embeds the target's email address for tracking. The campaign targeted SANS handlers directly, which is a nice bit of nerve. If you're not inspecting or sandboxing inbound SVGs, start.

Infostealers are becoming the default payload

Malwarebytes makes the case that attackers are moving away from login-page harvesting toward infostealer malware that silently lifts saved passwords, session cookies, autofill data, and wallet details straight off the device. Session-cookie theft is the key move, because it bypasses MFA entirely. There's no second factor to prompt when you're replaying a valid session token. This runs as a malware-as-a-service economy, the harvested data gets resold, and stolen mailbox access is a primary feeder for BEC. This is the same token-theft logic behind Kali365 from a couple of weeks back, now generalized into a business model.

The invoice scam with no link and no attachment

Malwarebytes caught a callback-phishing operation mid-build, templates still full of unfilled merge fields like `#TFN#` and `#PRICE#`. The emails claim an unauthorized charge from PayPal, Amazon, or Geek Squad (sometimes several at once) and push you to call a number to dispute it. On the phone, a fake agent works you for remote access or card details. There's no malicious link and no attachment, so link and attachment scanners have nothing to bite on. The phone number is the entire attack.

Fake copyright notices aimed at Chrome extension developers

A campaign impersonating Google and the Chrome Web Store tells developers their extension violates policy. Enter your extension ID to "verify" and the page pulls your extension's real name and icon from public Web Store data, then adds a fake complaint number and a 48-hour countdown to rush you into a Google sign-in. The goal is developer account takeover, which means the ability to push malicious updates to everyone who already installed the extension. Real warnings only ever appear in the developer dashboard, never by email.

  • Ten live AitM campaigns, mapped

    Identity Automation's Phish Wire broke down ten campaigns running late May into June, impersonating Microsoft 365, Azure AD, Outlook, GoDaddy, and others.

This roundup is published weekly by Red Sift. Test your email authentication set-up with Red Sift Investigate.