We just discovered a new trick that is currently being used to slip malicious html files through email security solutions and, in some cases, through antivirus engines. The trick is quite simple: declaring an email entity as “application/html” instead of “text/html”. “application/html” is an invalid type and this allows it to slip through some checks. […]
About Rodolfo Saccani
Before working in the security field Rodolfo Saccani lived and worked between US and Europe in heterogeneous technical fields: linux embedded systems, experimental avionics, secure telecommunication systems for hostile environments, smartTV, process control and industrial automation, clinical research, SaaS systems.
Rodolfo is also security officer in the Italian free flight organization, as CEN expert writes European norms for the certification of free flight equipement, he is also chairman of the European Safety and Training Committee of the European Hang-gliding and Paragliding Union.
In Libraesva Rodolfo manages research and development.
Entries by Rodolfo Saccani
What makes a good archiving solution? Count 1 to 10: 1- No vendor lock-in Archiving email is a long term commitment, you need to think long term and make sure that you will be able, in 10 or 20 years from now, to autonomously, easily and reliably make use of your email archive. If […]
Recent email phishing campaigns are using Google reCAPTCHA as part of their efforts to bypass click-time protection sandboxing, requiring user interaction before delivering the actual contents of the phishing page. We have seen two different instances of such campaigns, both are targeting Office 365 users in order to collect their credentials. Implementation details suggest that […]
Lots of differences, actually. An email backup is a snapshot of a specific point in time, it’s purpose is for recovery in case of a disaster. Email archiving does not archive a series snapshots but it preserves all data history. The purpose of the archiver is much broader: discovery, compliance, legal, search, analysis and for […]
It might be a targeted attack, given that we detected it only in one organization, or it might just be an ancient infection still attempting to propagate. In both cases it is an interesting case. The attack is coming via email, which is interesting given that it is a vbscript attack. Here is how the […]
Anything can be monetized online, especially the credentials of your email account. Here is how they are abused. Botnets are one of the main distribution channels for malware and phishing email. A botnet can be composed of hundreds of thousands of compromised devices (increasingly IoT devices) and the command-and-control (C&C) center coordinates the activity of […]
Tracking pixels, or beacons, are widely used in email advertising, but a more subtle and dangerous use is possible. Tracking pixels are basically very small images (usually invisible to the human) embedded in the email, whose content is loaded from a server when the email is opened. When your email client loads this image from […]
We spotted an instance of what appears to be a targeted attack through a phishing email delivering a .mobileconfig file. This is a file format used to deliver configurations to iphones. The attack originates from domain that appears to have been created just for this purpose. This is how the email appears to the recipient: […]
It’s almost one month now that a very effective malspam campaign delivering the ursnif trojan is in progress in Italy. The trick that the malware uses to spread is simple and effective: once run on the victim’s machine it sends replies to existing email threads attaching a copy of the malware itself. This strategy is […]
DDE (Dynamic Data Exchange) is a very old and almost forgotten feature of Microsoft Office. Designed to automate the exchange of data between applications, it can be easily exploited to execute arbitrary code without any macro or other active content. About one month ago, samples of office documents exploiting DDE to spread ransomware have been […]