Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
California Child Care Company Discovers 9-Year Employee Data Leak
Child Care Resource Center, a California non-profit, disclosed a nine-year data breach involving an employee forwarding internal files containing personal data to an external email account from October 2016 to October 2025. While the practice was intended to facilitate work duties rather than data theft, the organization lost control of sensitive information and cannot rule out unauthorized access
AINew CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
Security researchers have discovered new CSS-based attack vectors that allow malicious content within emails to break out of message boundaries and interact with webmail interfaces. These attacks affect major email providers including Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, enabling threat actors to steal passwords, hijack accounts, leak authentication tokens, and manipula
AICSS: The Hidden Threat Lurking in Your Inbox
Security researchers have identified CSS as an emerging threat vector for data exfiltration in webmail environments, moving beyond its traditional design-focused role. The vulnerability exploits CSS capabilities to extract sensitive information from email clients, with some vendors lacking adequate protections against these attacks.
AIFree Webinar: HIPAA Compliant Email – What you Actually Need (Without an IT Team)
A free webinar scheduled for August 7, 2026, will address how small healthcare practices can achieve HIPAA-compliant email without dedicated IT staff. The session will explain why standard email solutions like Gmail and Microsoft 365 are insufficient for HIPAA compliance and demonstrate practical approaches to closing security gaps while maintaining ease of use for both staff and patients.
AIRussian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
Russian threat actors have been exploiting a vulnerability in Microsoft Outlook Web Access (OWA) to maintain persistent access to mailboxes even after credential rotation. The campaign, which started in July 2026, targets U.S. and European government entities along with telecommunications, financial, hospitality, and aerospace sectors. These same actors were previously linked to exploiting a Zimbr
AICloudflare DMARC Management is now generally available
Cloudflare has made its DMARC Management solution generally available with enhanced features to help organizations achieve full email authentication enforcement. The platform addresses the growing requirement from major email providers like Google, Microsoft, and Yahoo for proper DMARC, SPF, and DKIM configuration, offering free tools that eliminate the need for costly consultants or manual XML re
Data Breaches Announced by Two Digestive Health Companies
Two digestive health organizations, Gastro Health and Spokane Digestive Disease Center, have disclosed separate data breaches resulting from phishing attacks and unauthorized email account access. Both incidents exposed sensitive patient information including Social Security numbers, medical records, and financial data, affecting thousands of individuals across multiple states. The breaches occurr
AIMicrosoft Exchange Flaw Lets Attackers Spoof Any Email Address
A vulnerability dubbed 'Ghost-Sender' has been discovered in Microsoft Exchange that allows attackers to spoof any email address. The flaw specifically affects Exchange Online or on-premises deployments running in hybrid mode when configured with third-party mail servers or spam filters, enabling sophisticated email impersonation attacks.
AIGoogle DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT
A new malspam campaign is exploiting Google's DoubleClick domain to bypass security detection systems and deliver the DesckVB remote access trojan (RAT). The attack leverages the trusted reputation of Google-owned infrastructure to route malicious traffic before redirecting victims to attacker-controlled servers. This technique exploits the fact that many enterprise security tools whitelist or dep
AIGlobal Stock Exchange Hit by Monthslong Email Campaign
A sophisticated threat actor compromised a senior finance executive's email account at a global stock exchange, maintaining persistent access over several months. The attack leveraged legitimate Windows native tools to evade detection, providing the attacker with continuous visibility into sensitive financial communications and potentially market-moving information.
Patient Data Exposed in Cyberattacks on Dental Practices
Three dental practices—Bridle Trails Family Dentistry, Verber Dental Group, and Bronsky Orthodontics—have disclosed data breaches affecting over 32,700 patients combined. The incidents involved unauthorized access to email accounts and network environments, exposing protected health information including names, Social Security numbers, medical records, and insurance details. All three organization