Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2618+ Articles
162+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
22 articles

#Email Security

All CosmicBytez Labs articles tagged #Email Security, across news, security advisories, how-to guides, and projects.

  • SecurityAug 29, 2026

    CVE-2026-42007: Critical Use-After-Free in Dovecot's Sieve Editheader Extension

    Dovecot's Sieve editheader extension has a critical use-after-free (CVSS 9.1) letting authenticated users corrupt memory during mail delivery.

  • SecurityAug 28, 2026

    CVE-2026-82082: Critical Unauthenticated OS Command Injection in NUMail

    Unauthenticated OS command injection in Green-Computing's NUMail lets remote attackers run arbitrary commands on the mail server. CVSS 9.8.

  • SecurityAug 22, 2026

    CVE-2026-73570: Zimbra ZCS OS Command Injection via SMTP

    Zimbra Collaboration Suite contains a critical unauthenticated OS command injection flaw allowing RCE as the Zimbra user via crafted SMTP requests.

  • NewsAug 20, 2026

    Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

    CVE-2026-73570, a CVSS 8.9 command injection flaw in Zimbra Collaboration, is actively exploited in the wild for unauthenticated RCE via SNMP.

  • NewsAug 8, 2026

    New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

    PortSwigger researcher Gareth Heyes demonstrated at Black Hat USA 2026 that CSS and HTML within emails can escape message boundaries to capture typed passwords, steal session tokens, and leak IP addresses across Outlook, Gmail, Yahoo, Proton Mail, Fastmail, and AOL Mail.

  • NewsJul 26, 2026

    Russian APT 'Laundry Bear' Exploited Zimbra Zero-Day with Half-Click Email Attack

    Russia-backed Laundry Bear (Void Blizzard/TA488) exploited CVE-2025-66376 — a stored XSS flaw in Zimbra's Classic UI — to compromise US, Ukrainian, and NATO targets. The 'half-click' attack triggers just by opening an email, bypasses MFA, and plants a persistent backdoor credential.

  • NewsJul 25, 2026

    AegisAI Raises $36 Million for AI-Powered Email Security

    AegisAI has closed a $36 million funding round led by Battery Ventures, Accel, and Foundation Capital, bringing the company's total raise to $49 million...

  • NewsJul 24, 2026

    AegisAI Raises $36 Million to Fight AI-Crafted Phishing with AI Defenses

    AegisAI has closed a $36M Series A, bringing total funding to $49M, to scale its AI agent-based email security platform purpose-built to counter the rise...

  • NewsJul 23, 2026

    Russian Laundry Bear Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

    A Russian state-sponsored espionage group spent months silently reading Western mailboxes through a zero-click XSS flaw in Zimbra's webmail client —...

  • NewsJul 11, 2026

    Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions

    A critical stored XSS vulnerability in Zimbra's Classic Web Client allows attackers to deliver specially crafted emails that execute arbitrary code within...

  • NewsJul 10, 2026

    Zimbra Urges Customers to Patch Critical Web Client XSS Flaw Exploited in the Wild

    CVE-2025-27915, a stored XSS vulnerability in Zimbra's Classic Web Client, was exploited as a zero-day before public disclosure. Attackers used malicious...

  • NewsJul 7, 2026

    Major Japanese Telco Cyberattack Exposes 12 Million Email Accounts

    A cyberattack on a major Japanese telecommunications provider compromised an email management system affecting five ISPs, exposing the accounts, webmail...

  • NewsJun 28, 2026

    Data Breach Exposes Up to 14.2 Million Email Logins at Six ISPs

    Japanese telecom giant KDDI Corporation disclosed a data breach affecting up to 14.22 million email accounts across six ISPs — including Nifty, Biglobe,...

  • NewsMay 19, 2026

    SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE

    Critical security vulnerabilities in SEPPMail Secure E-Mail Gateway — an enterprise email security appliance — could allow attackers to achieve remote...

  • NewsMay 16, 2026

    Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild

    Microsoft has shared mitigations for CVE-2026-42897 until a permanent patch can be released for affected Exchange Server versions actively being targeted...

  • NewsMay 15, 2026

    Microsoft Warns of Exchange Zero-Day Flaw Exploited in Attacks

    Microsoft shared mitigations for a high-severity Exchange Server vulnerability being actively exploited that allows threat actors to execute arbitrary...

  • NewsMay 13, 2026

    New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution

    Exim has released security updates to patch a severe vulnerability affecting GnuTLS-compiled builds of the world's most widely deployed mail transfer...

  • SecurityMay 9, 2026

    CVE-2026-42193: Plunk Email Platform SNS Webhook Forgery

    A critical unauthenticated vulnerability in Plunk, the open-source AWS SES email platform, allows attackers to forge Amazon SNS webhook payloads without...

  • NewsApr 26, 2026

    Over 10,000 Zimbra Servers Vulnerable to Ongoing XSS Attacks

    CISA has confirmed that a cross-site scripting vulnerability in Zimbra Collaboration Suite is being actively exploited in the wild, with over 10,000...

  • HOWTOApr 20, 2026

    Email Authentication: Deploying SPF, DKIM, and DMARC to Stop Spoofing

    Step-by-step guide to implementing SPF, DKIM, and DMARC on your domain — eliminate email spoofing, prevent phishing, and gain full visibility into who...

  • SecurityFeb 5, 2026

    Microsoft Exchange Server SSRF to RCE Chain Actively

    A server-side request forgery vulnerability in Exchange Server is being chained with deserialization flaws for unauthenticated remote code execution....

  • HOWTOFeb 3, 2026

    Exchange Online Security Hardening for Enterprise

    Secure your Exchange Online environment with mail flow rules, anti-spam policies, DMARC enforcement, admin audit controls, and mailbox permission hardening.