🟠 High | Source: The Register — Security
A year-long Russian-linked phishing campaign has been exploiting a vulnerability that allows malware to execute simply by a user previewing or opening an email, without clicking any link or attachment. The technique likely abuses zero-click or render-time exploitation, making it exceptionally dangerous as traditional user-awareness training offers little protection. Organisations relying on standard email security controls may be inadequately protected against this class of attack.
Security Architect’s Take: Review your email security stack immediately — ensure advanced sandboxing and pre-delivery detonation are enabled in your mail gateway (Microsoft Defender for Office 365, Google Workspace’s pre-delivery scanning, or equivalent), and consider enforcing plain-text email rendering policies to reduce the HTML/script attack surface. Audit mail flow rules to ensure external HTML content and remote resource loading are blocked at the gateway level.
Original advisory: Year-long Russian attacks infect users as soon as they look at an email