Threat Intelligence

Gateway threat blog

Analysis of active campaigns, zero-day phishing techniques, and gateway detection updates from the Orangeburg Secure research team.

June 28, 2026
CriticalPhishing

QR code phishing surge: 340% increase in Q2

Attackers are embedding malicious QR codes in PDF attachments to bypass URL scanners that only analyze plaintext links. Our gateway now renders and scans QR payloads in sandboxed PDF parsers.

June 22, 2026
BECCampaign

CEO impersonation campaign targeting fintech

A coordinated BEC campaign spoofed executive domains across 47 organizations. Header anomaly detection and reply-to mismatch rules blocked 2,100 messages before delivery.

June 15, 2026
CriticalMalware

HTML smuggling in calendar invites

Threat actors embed JavaScript payloads in .ICS calendar attachments. Updated sandbox rules now detonate calendar files and extract embedded script content.

June 8, 2026
Intel

DMARC enforcement gaps in Fortune 500

Our aggregate analysis of 500 enterprise domains shows 38% still publish p=none. We outline a 30-day path to p=quarantine without disrupting legitimate mail flow.

May 30, 2026
Phishing

Microsoft 365 credential harvesters evolve

New kit uses CAPTCHA gates and geofencing to evade automated scanners. Gateway URL rewrite now follows redirect chains up to 5 hops with headless browser verification.

May 22, 2026
Product

Webhook events for real-time SOAR integration

threat.detected and quarantine.created webhooks now include full IOC data — sender reputation, attachment hashes, and campaign cluster IDs for automated playbook triggers.