Hear from Let's Encrypt on shorter certificate lifecycles, CLM automation, and the post-quantum push - Watch on demand 
Site logo
Site logo
  • Products
  • Free Tools
  • Love
  • Resources
  • MSPs & Partners
Log InLog In
Sign Up
Get a demoGet a demo
Log In
Sign Up
Products
Free Tools
Love
Resources
MSPs & Partners
EN
EN

Latest issue

What's happening in email security: July 13 – July 19, 2026

July 20, 2026

When a password manager has to warn its own users about a phishing campaign wearing its name, you know brand impersonation is the whole game. LastPass did exactly that this week. Microsoft shipped a record Patch Tuesday with yet another crafted-email Exchange flaw, two Scattered Spider members got real prison time, and a flaw in an AI browser assistant quietly opened a path to reading Gmail. Plenty to get through.

Read the latest issue
Email Security Weekly issue #020 for July 13 - July 19, 2026. Key email security developments from Red Sift.

Archive

Past Email Security Weekly issues

19 issues

Email Security Weekly issue #020 for July 13 - July 19, 2026. Key email security developments from Red Sift.

July 20, 2026

What's happening in email security: July 13 – July 19, 2026

When a password manager has to warn its own users about a phishing campaign wearing its name, you know brand impersonation is the whole game. LastPass did exactly that this week. Microsoft shipped a record Patch Tuesday with yet another crafted-email Exchange flaw, two Scattered Spider members got real prison time, and a flaw in an AI browser assistant quietly opened a path to reading Gmail. Plenty to get through.

Read issue
Email Security Weekly issue #019 for July 6 - July 12, 2026. Key email security developments from Red Sift.

July 13, 2026

What's happening in email security: July 6 – July 12, 2026

The phishing email is increasingly just the opening move. This week's standout attack started with a survey email and ended with a fake IT-support call on Microsoft Teams. Elsewhere, scammers impersonated Robinhood with no links at all, and the device-code and encrypted-payload techniques we've been tracking kept mutating to stay ahead of the gateway. If your email defense stops at the inbox, several of these walk right past it.

Read issue
Email Security Weekly issue #018 for June 29 - July 5, 2026. Key email security developments from Red Sift.

July 6, 2026

What's happening in email security: June 29 – July 5, 2026

Last week the story was that phishing can pass your authentication checks. This week it's the sequel: once an attacker has a token, they don't need to phish you again. A ToddyCat tool quietly read corporate Gmail by riding an OAuth session, a Russia-linked crew phished Ukrainian targets with booby-trapped remote-desktop files, and a flaw in Apple's Hide My Email re-exposed the addresses it was built to hide. The through-line on the token story is persistence: modern email compromise is increasingly about holding access, not just getting in.

Read issue
Email Security Weekly issue #017 for June 22 - June 28, 2026. Key email security developments from Red Sift.

June 29, 2026

What's happening in email security: June 22 – June 28, 2026

Here's a sentence to ruin an email admin's afternoon: this week produced phishing that passed SPF, DKIM, and DMARC cleanly, plus a separate kit that sidesteps MFA without ever breaking it. Microsoft named the first technique "authentication laundering." The second, a device-code phishing platform, posted a 1,380% growth chart. Attackers also spent the week hiding lures inside Microsoft 365 Groups and calendar invites. If you've been treating an authentication pass or an MFA prompt as proof of trust, this is the week to stop.

Read issue
Email Security Weekly issue #016 for June 15 - June 21, 2026. Key email security developments from Red Sift.

June 22, 2026

What's happening in email security: June 15 – June 21, 2026

Two of this week's stories share an uncomfortable theme: the tools meant to help you handle email can be turned into ways to steal it. A Microsoft 365 Copilot flaw let a single click drain a mailbox, and a widely installed WordPress plugin leaked the credentials companies use to send mail. Add a billion-dollar phishing takedown and an Apple change that affects your allowlists, and it's a fuller week than the headline count suggests.

Read issue
Email Security Weekly issue #015 for June 8 - June 14, 2026. Key email security developments from Red Sift.

June 15, 2026

What's happening in email security: June 8 – June 14, 2026

Remember the Exchange zero-click we flagged in May, the one with no patch and a mitigation that broke calendar printing? It finally has a real fix. Microsoft shipped it as part of a 200-CVE Patch Tuesday that quietly cleaned up several more Exchange spoofing bugs, INTERPOL took 201 people off the board in a PhaaS sweep, and Google put a number on the fraud problem that's hard to unsee: roughly $580 billion lost worldwide last year.

Read issue
Email Security Weekly issue #014 for June 1 - June 7, 2026. Key email security developments from Red Sift.

June 8, 2026

What's happening in email security: June 1 – June 7, 2026

No breach dominated this week and no vendor shipped an emergency patch. What we got instead was a clear picture of where phishing actually is in mid-2026, and it's not the fake login page you're picturing. Attackers spent the week delivering JavaScript inside image files, skipping links entirely for phone numbers, and swapping credential-harvesting pages for malware that just takes the session cookie. The login prompt is optional now.

Read issue
Email Security Weekly issue #013 for May 25 - May 31, 2026. Key email security developments from Red Sift.

June 1, 2026

What's happening in email security: May 25 – May 31, 2026

Three things stood out this week. Scammers are already industrializing the 2026 World Cup with hundreds of fake FIFA sites, phishing found a new home inside AI assistants, and France drew a hard line on the tracking pixel that quietly sits in most marketing email. A busy end to the month, so let's get into it.

Read issue
Email Security Weekly issue #012 for May 18 - May 24, 2026. Key email security developments from Red Sift.

May 25, 2026

What's happening in email security: May 18 – May 24, 2026

The FBI doesn't issue a public warning about a phishing kit every week. This week it did, because Kali365 steals your Microsoft 365 access without ever touching your password or tripping MFA. Meanwhile a business professional in Singapore wired away S$4.9 million after a video call with people who were not real, and on-prem Exchange admins spent the week without a patch for an actively exploited flaw. The connecting thread: the login prompt is no longer where attacks are won or lost.

Read issue
Email Security Weekly issue #011 for May 11 - May 17, 2026. Key email security developments from Red Sift.

May 18, 2026

What's happening in email security: May 11 – May 17, 2026

DMARCbis is finally an RFC. Mail servers also had a rough week. Microsoft disclosed an actively exploited Exchange zero-click that fires when a user opens a crafted email in Outlook Web Access, Exim shipped a fix for a CVSS 9.8 remote code execution flaw triggered by a single TLS quirk, and a Belarus-aligned APT spent the spring running geofenced PDF phishing against Ukrainian government targets. If you run your own email infrastructure, you have patching and reading to do.

Read issue
Email Security Weekly issue #010 for April 27 - May 3, 2026. Key email security developments from Red Sift.

May 4, 2026

What's happening in email security: April 27-May 3, 2026

Two of this week's biggest phishing campaigns passed DMARC, SPF, and DKIM. Not because the authentication checks failed, but because the emails came from real senders. AppSheet shipped the attacker's lure for them. PayPal shipped it directly.

Read issue
Email Security Weekly issue #008 for April 13 - April 19, 2026. Key email security developments from Red Sift.

April 20, 2026

What's happening in email security: April 13-19, 2026

Attackers don't need to keep logging in. Once they've cracked an M365 account, they're planting mailbox rules within seconds of first access, and those rules survive password resets. They keep quietly siphoning vendor threads long after the incident has been "closed."

Read issue
Email Security Weekly issue #007 for April 6 - April 13, 2026. Key email security developments from Red Sift.

April 14, 2026

What's happening in email security: April 6–13, 2026

Three separate threat actors ran adversary-in-the-middle campaigns in seven days. State actors, commercial PhaaS operators, and financially motivated criminals. AitM has graduated from sophisticated technique to standard issue. And this week, Microsoft documented what happens when you combine it with AI-generated lures at scale.

Read issue
Email Security Weekly issue #006 for March 30 - April 5, 2026. Key email security developments from Red Sift.

April 6, 2026

What's happening in email security: March 30 – April 5, 2026

Attackers don't need custom malware when legitimate software does the job. This week's most active campaign delivered trusted remote management tools to 80+ US organizations by hiding them inside fake party invitations. The emails looked like Punchbowl. The links went through HubSpot. The payload was LogMeIn. None of it would look wrong to most security tools.

Read issue
Email Security Weekly issue #005 for March 23 - March 29, 2026. Key email security developments from Red Sift.

March 30, 2026

What's happening in email security: March 23–29, 2026

Russia's FSB expanded their spear-phishing playbook to include an iOS exploit kit. In the same week, Iran-linked hackers compromised the FBI Director's personal email through a recycled password. Different actors, different targets, same gap: high-value individuals reached through channels that enterprise security doesn't cover.

Read issue
Email Security Weekly issue #004 for March 16 - March 22, 2026. Key email security developments from Red Sift.

March 23, 2026

What's happening in email security: March 16-22, 2026

Email authentication passed. The phishing still landed. That's the uncomfortable headline from this week. It's about attackers using Microsoft's own infrastructure to send phishing emails that pass every authentication check you have.

Read issue
Email Security Weekly issue #003 for March 9 - March 15, 2026. Key email security developments from Red Sift.

March 16, 2026

What's happening in email security: March 9-15, 2026

Attackers keep moving credential theft onto infrastructure defenders are reluctant to block. This week that meant a phishing kit built as a React app, hosted on Cloudflare Workers, and exfiltrating passwords through EmailJS. At the same time, the market data is clear on the defender side too: post-delivery cleanup, analyst workload, and identity-layer controls are now where email security programs win or lose.

Read issue
Email Security Weekly issue #002 for March 2 - March 8, 2026. Key email security developments from Red Sift.

March 9, 2026

What's happening in email security: March 2–8, 2026

Microsoft blocked more than 30 million Tycoon 2FA phishing emails in a single month. This week, law enforcement took the platform down. Competing AitM services are already filling the gap.

Read issue
Email Security Weekly issue #001 for February 23 - March 21, 2026. Key email security developments from Red Sift.

March 3, 2026

What's happening in email security: February 23 - March 1, 2026

APT28 spent five months beaconing victims through a developer tool nobody blocks. Meanwhile, the Sophos numbers confirm what most practitioners already sense: BEC is accelerating, and identity is still the primary attack surface.

Read issue

Want email security news in your inbox every week?

Subscribe here and stay up to date with what's happening in email security.

red sift logo
Products
Red Sift OnDMARC

Protect against phishing and BEC attacks.

Red Sift Brand Trust

Stop brand abuse, fraud, and other lookalike attacks.

Red Sift Certificates

Real-time discovery and seamless monitoring for certificates.

Red Sift ASM

Discover and manage external facing and cloud assets.

Red Sift Radar

The skilled up LLM that finds and fixes security issues 10x faster.

Free tools
Red Sift InvestigateBIMI CheckerSPF CheckerRadar LiteMicrosoft CheckerSubdoMailing CheckerRed Sift Certificates Lite
Love
Case StudiesSuccess Team
Resources
Resource CenterBlogGuidesEventsNews & ReportsGet Gartner print
Company
About UsAdvisory teamBoard & InvestorsCareersSustainabilityContact Us
MSPs & Partners
Our PartnershipsMSP ProgramPartner Portal Login
Ask AI for a summary of Red Sift
ChatGPT AI searchClaude AI searchPerplexity AI searchGemini AI searchGrok AI searchTrace Carbon Measured logo
  • Legal
  • Privacy
  • Cookies
  • Security & TrustIcon
  • Responsible disclosurelink arrow
  • Statuslink arrow
  • Developer documentationlink arrow
Copyright © 2026 Red Sift