Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Warning: Compromised Hotel Routers Send Users to Phishing Sites

Attackers are using compromised hotel Wi-Fi routers to redirect users to Microsoft 365 phishing sites, according to researchers at ReliaQuest. The attacks were observed in multiple U.S. cities, as well as across India and Saudi Arabia. These types of DNS poisoning attacks can send users to phishing sites with very little evidence that something suspicious has taken place.

Is Yahoo Email Secure?

Yahoo email may not be the most popular email option in 2026, but it is still an active service with millions of users. If it is on your list of potential email providers, this article will cover: If you’re looking for an end-to-end encrypted email specifically, you can try Internxt Mail, now with an 85% discount on all Ultimate monthly and annual plans, which includes 5TB of encrypted storage and access to all of Internxt's features. Get 85% off all Internxt plans.

8 Best Encrypted Email Services to Protect Yourself With In 2026

Most successful hacks and data breaches are perpetrated through email. In a perfect world, everyone would find safer methods for communication, but since email isn't going anywhere anytime soon, encrypted email is our best option. Since Internxt doesn't have its own encrypted email yet, we've assembled a list of the best encrypted email services you should use in the meantime.

The Industrialized Fraud Hiding in Plain Sight

To read more on this story and the significance of Business Email Compromise (BEC), visit The Wall Street Journal where Dave Burg was interviewed (subscription required). A few months ago, scammers hijacked a routine infrastructure project in Surfside Beach, South Carolina, costing the small town $545,000. The scheme stemmed from a single spoofed email sent from a lookalike domain, instructing the town to switch payment from check to ACH.

The Blind Spot: How "Bulletproof" Phishing Redirectors Slip Past SEGs

By Shikhar Dalela and Jeewan Singh Jalal The operators named the kit themselves. Buried inside compromised legitimate websites, the hidden staging directory is sometimes literally called “/.bulletproof”, and the PHP session cookie the kit sets on every visitor is named “bp_redir_sess.” The “bp” stands for bulletproof, which is an unusual degree of candor from a threat actor whose entire design philosophy is concealment.

Is Outlook Secure and Should You Use It for Private Emails?

Outlook is part of the Microsoft ecosystem of OneDrive, Teams, SharePoint, Word, Excel, PowerPoint, and Copilot. It offers plans for individuals, families, and businesses and cloud storage of up to 6TB. For this article, we will cover is Outlook secure for your needs, whether you need an email service with end-to-end encryption for your privacy needs, and the following topics.

Why Modern Email Security Requires More Than Sender Reputation

For years, email filtering worked from a stable premise: malicious messages would expose themselves through something observable. A suspicious domain, a spoofed sender, a known-bad attachment or a URL with poor reputation gave defenders a concrete signal to block. Those controls still stop commodity phishing. What has changed is that many convincing attacks now inherit trust rather than imitate it.

4 Simple Habits To Stop Email Hackers

Stopping email hackers requires adopting four specific habits: letting AI filter inbound messages, identifying manufactured urgency, verifying requests through second channels, and locking accounts with passkeys. These zero-skill routines block the credential-harvesting tactics that compromise shopping, streaming, and financial profiles. Consider a content creator receiving a brand partnership offer from a recognizable sportswear company. The logo perfectly matches the corporate website, the tone sounds professional, and the message includes a simple link labeled to review the contract.

Payroll Pirates: Strange New Tides in Business Email Compromise

Arctic Wolf is tracking an ongoing Microsoft 365 phishing campaign affecting healthcare, education, manufacturing, government, professional services, and other sectors across the United States, Canada, and Europe. In July 2026, we observed hundreds of organizations being targeted by email, with successful intrusions identified across a broad range of environments.