30
Search: “Content Authenticity Initiative”
355 stories
35
35
35
45
30
45
30
30
30
30
30
30
30
30
45
45
30
30
30
New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Virus Bulletin Q3 2026 report details phishing using DKIM-aligned senders, Amazon SES delivery, and real-time URL cloaking to evade email security and scanners.
Virus Bulletin's Q3 2026 testing found phishing campaigns delivered through trusted infrastructure like Amazon SES with DKIM-aligned sender domains. Samples included a German overdue-invoice lure redirecting to OpenSea crypto fraud and a Romanian BCR-branded PSD2 banking credential-theft campaign. Cloaking pages used hidden iframes, browser fingerprinting, and time-zone checks to show different content to scanners versus victims. Defenders are urged to inspect full redirect chains rather than attachments or initial URLs alone.
45
30
30
30
30
30
30
30
30
30
30
30
30
30
30
30
30
30
30
45