Phishing the Supply Chain: Is Your Vendor Email Security an Invitation for Threat Actors?
ID: ade7bbdd-c7ee-5eae-b585-44da9e998426
STIX ID: report--ade7bbdd-c7ee-5eae-b585-44da9e998426
Feed Name: CloudSEK Blog
Threat Score
CloudSEK's SVigil discovered a misconfigured SPF record (soft-fail ~all) on a logistics SaaS provider's primary domain, which could allow attackers to spoof the vendor's emails and enable business email compromise, targeted phishing, malware distribution, and brand blacklisting; the report recommends switching to SPF hard-fail (-all), deploying DKIM, enforcing strict DMARC (p=reject/quarantine) and continuously monitoring DMARC reports.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
