< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-07-08T18:30:00+05:30

EvilTokens Campaign Exploits Browser-Level Vulnerabilities in Email Security

A new 'ghost phishing' technique exploits browser-level decryption to bypass traditional email security checks, hiding malicious content until it is rendered in the victim's browser. The attack uses AES-GCM encryption to conceal phishing pages, allowing Microsoft 365 account takeovers without direct password theft, posing significant risks to enterprises.

A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser.

For security leaders, the risk is clear: traditional URL checks may miss the attack while Microsoft 365 access, sensitive data, and response time

Read original article

*** END OF TRANSMISSION ***