QR code phishing surge: 340% increase in Q2
Attackers are embedding malicious QR codes in PDF attachments to bypass URL scanners that only analyze plaintext links. Our gateway now renders and scans QR payloads in sandboxed PDF parsers.
Analysis of active campaigns, zero-day phishing techniques, and gateway detection updates from the Orangeburg Secure research team.
Attackers are embedding malicious QR codes in PDF attachments to bypass URL scanners that only analyze plaintext links. Our gateway now renders and scans QR payloads in sandboxed PDF parsers.
A coordinated BEC campaign spoofed executive domains across 47 organizations. Header anomaly detection and reply-to mismatch rules blocked 2,100 messages before delivery.
Threat actors embed JavaScript payloads in .ICS calendar attachments. Updated sandbox rules now detonate calendar files and extract embedded script content.
Our aggregate analysis of 500 enterprise domains shows 38% still publish p=none. We outline a 30-day path to p=quarantine without disrupting legitimate mail flow.
New kit uses CAPTCHA gates and geofencing to evade automated scanners. Gateway URL rewrite now follows redirect chains up to 5 hops with headless browser verification.
threat.detected and quarantine.created webhooks now include full IOC data — sender reputation, attachment hashes, and campaign cluster IDs for automated playbook triggers.