The Email That Passed Every Security Check (Because Adobe Sent It)
ID: bc887f2f-c330-54ed-9b4a-2eb0421cb36d
STIX ID: report--bc887f2f-c330-54ed-9b4a-2eb0421cb36d
Feed Name: IRONSCALES
A targeted spearphishing campaign leveraged Adobe's legitimate emailing and redirect services (Amazon SES-sent, DKIM/SPF/DMARC-validated adobe.com messages) to deliver personalized credential-harvesting lures to a K‑12 school district; links used postoffice.adobe.com with JWT-encoded destinations that appeared benign to URL scanners. IRONSCALES' semantic analysis and community telemetry flagged and quarantined the messages across four mailboxes before credentials were harvested, illustrating how "living-off-trusted-services" attacks bypass authentication- and reputation-based controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
