When 'Release from Quarantine' Is the Attack
ID: eb8971dc-0a36-5d5f-9266-3a3e4ca38387
STIX ID: report--eb8971dc-0a36-5d5f-9266-3a3e4ca38387
Feed Name: IRONSCALES
Threat Score
The report details a high-risk phishing campaign impersonating email quarantine digests from serverdata.net: attackers sent messages with JWT-bearing "Allow"/"Manage" action links pointing to co.quarantine.serverdata.net while displaying legitimate-looking email addresses, enabling credential harvesting across multiple organizations and evading simple detection via realistic domain/authentication signals.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
