Issue #015June 15, 2026
VP of Marketing, Rebecca WarrenRebecca Warren

What's happening in email security: June 8 – June 14, 2026

Remember the Exchange zero-click we flagged in May, the one with no patch and a mitigation that broke calendar printing? It finally has a real fix. Microsoft shipped it as part of a 200-CVE Patch Tuesday that quietly cleaned up several more Exchange spoofing bugs, INTERPOL took 201 people off the board in a PhaaS sweep, and Google put a number on the fraud problem that's hard to unsee: roughly $580 billion lost worldwide last year.

Microsoft finally patches the actively exploited Exchange OWA zero-day

CVE-2026-42897 now has a permanent fix. Microsoft released it on June 9 for on-premises Exchange Server 2016, 2019, and Subscription Edition. If you've been running the Emergency Mitigation Service URL rewrite rule since mid-May and living with the broken calendar printing and disabled OWA Light, you can stop.

This is the same flaw CISA added to its Known Exploited Vulnerabilities catalog on May 15 with a May 29 deadline for federal agencies. It's a cross-site scripting bug in the OWA rendering pipeline, CVSS 8.1, exploited by sending a crafted email that runs JavaScript in the victim's authenticated browser session when they open it. No link to click, no attachment. Exchange Online was never affected.

If you run Exchange on-prem, apply the June update and then confirm the mitigation rule didn't leave anything in a broken state. Two-step job, and worth doing this week.

June Patch Tuesday cleaned up more Exchange spoofing along the way

The same release fixed 200 vulnerabilities total, six of them zero-days. Buried in that pile were three more Exchange Server spoofing flaws: CVE-2026-45500, CVE-2026-45501, and CVE-2026-47631. None were being exploited, but the pattern is the point. Attackers keep probing the mail server layer, and one cycle patching four separate Exchange bugs tells you where the pressure is. Prioritize the Exchange items inside that batch.

A stock exchange executive's mailbox was quietly drained for five months

Check Point reported an espionage operation that siphoned a senior executive's Outlook mailbox at a major global stock exchange for roughly five months before anyone noticed. The attackers used legitimate cloud storage services and disguised the exfiltration as routine update tasks, moving data out in small batches. This is the archetypal high-value email breach: quiet, long-dwell, and invisible to gateway controls because the attacker is already inside a trusted mailbox. It's the strongest argument going for mailbox-level anomaly detection and watching your OAuth and cloud-storage exfiltration paths, not just your inbound mail flow.

INTERPOL dismantled Sniper Dz and arrested 201 people

Operation Ramz ran from October 2025 to February 2026 and ended with 201 arrests across 13 countries in the Middle East and North Africa, including Sniper Dz's lead developer, arrested by Algerian police. The platform had operated since at least 2015, collected more than 45,000 victim records, and was linked to over 20,000 domains. It handed low-skilled attackers 80 phishing templates in five languages, mostly impersonating PayPal, Facebook, Instagram, Netflix, and Steam. This is the commodity infrastructure that drives a huge share of consumer brand impersonation, so taking it down actually moves the needle.

Google put a price tag on the fraud economy

Google's June fraud advisory is worth reading in full. The headline number is an estimated $580 billion in global fraud losses for 2025, with about one in five adults hit by a scam. The tactics have moved on from classic credential phishing. Google is now tracking Adversary-in-the-Middle attacks that steal session tokens, QR-code "quishing," fake renewal notices dropped straight into Google Calendar invites, and malicious instructions hidden inside cloud documents to slip past filters. There's also a wave of "digital arrest" scams spoofing law enforcement across South and Southeast Asia and the Gulf. When a mailbox provider documents its own detection priorities like this, treat it as a roadmap for yours.

  • One in five phishing links slips past legacy filtering

    Menlo Security's 2026 Browser Threat Report found roughly one in five phishing links users actively clicked went completely undetected by legacy URL filtering, drawn from millions of Q1 browser sessions, making the case for layering session-level protection on top of your gateway and authentication.

This roundup is published weekly by Red Sift. Test your email authentication set-up with Red Sift Investigate.