Tech News
← Home  ·  All topics

Email

31 GoKawiil briefs on this topic

Aikido Security finds GitLab issue-creation email addresses can grant account-level access

Aikido Security published research showing that GitLab's per-user incoming email address, meant to let users create project issues via email, contains a non-expiring token that functions as an authentication and authorization credential. Because GitLab treats any message sent to that address as coming from its owner, exposure of the address alone can let an attacker create issues, submit merge requests, or send patch files across an organization's public and private projects without needing account credentials.

Opinion piece argues AI is better suited to fact-checking than creative tasks

A commentator argues that since ChatGPT's 2022 launch, people have largely used AI for creative tasks like brainstorming, writing emails, and building strategies from scattered notes. The author contends this is the wrong use case, suggesting AI should instead handle routine, verifiable work where machines outperform humans.

Microsoft seizes 50 EvilTokens phishing sites, two arrested in UK

Microsoft and partner organizations dismantled EvilTokens, a phishing-as-a-service operation that used AI tools and device code phishing to compromise over 12,000 inboxes across more than 10,000 organizations. Following a US court-enabled legal action, Microsoft seized 50 websites and disabled over 150 additional domains linked to the operators, tracked as Storm-2992. The UK's Metropolitan Police also arrested two men connected to the scheme this month; both were released on bail pending further investigation.

Pangram launches Gmail integration to flag AI-generated emails

Pangram, an AI-detection service, has released a new integration for Gmail that scans incoming messages and flags those it believes were written by artificial intelligence. The tool aims to help users quickly identify AI-generated 'slop' mixed in with genuine human correspondence.

Cisco patches actively exploited zero-day in Secure Email Gateway software

Cisco released fixes for CVE-2026-76461, a critical flaw in AsyncOS Software for Secure Email Gateway that lets unauthenticated attackers run root-level commands by sending crafted emails with malicious SQL statements. The company confirmed it detected active exploitation of the bug in September 2026 and issued indicators of compromise for defenders to check mail logs and network traffic. CISA has added the flaw to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 17 to patch.

Outlook's 'message can't be displayed' error fixed by clearing cache

Microsoft Outlook users encountering the 'Your message can't be displayed right now' error can resolve it by clearing their cache, whether they use the web version or the desktop client. The fix forces Outlook to rebuild fresh copies of emails without deleting any messages, calendar events, or contacts.

Microsoft finds AI-driven phishing campaign sent 1 million personalized invoices in 3 days

Microsoft researchers uncovered a phishing operation in which an unidentified attacker sent over one million fraudulent emails within three days, each tailored to target accounts payable staff at specific companies. The emails impersonated ServiceNow, demanding nearly $50,000 in fake subscription payments, and included fabricated email threads featuring real executives' names to make the scam appear legitimate.

Entrepreneur Op-Ed Argues Value-Led Content Beats AI-Driven Cold Outreach in 2026

An Entrepreneur contributor argues that mass-personalized AI outreach, like generic cold LinkedIn messages and spam emails, is damaging brand credibility rather than building it. Instead, the piece advocates for marketing built on educational content and showcasing real client success stories to attract buyers who are already primed to purchase.

Trezor's email vendor breached, used to send fake security-alert phishing emails

Trezor alerted customers that attackers compromised its third-party email provider and used the legitimate [email protected] address to send phishing emails warning of a fake 'STM32 Entropy Vulnerability' in its hardware wallets. The company took down the malicious domain and is investigating how attackers gained access to its email infrastructure. This follows an earlier breach disclosed in August involving shipping partner ShipMonk, which exposed personal data of roughly 81,000 customers across multiple countries.

Instinct AI assistant gains its own email address to manage accounts autonomously

Instinct, the AI assistant startup valued at $2.5 billion, announced it is issuing dedicated email addresses to its agent so it can independently sign up for services, contact businesses, and handle bookings without flooding users' personal inboxes. Founder Noah Shinn said this is the first step toward letting Instinct fully own and operate accounts on a user's behalf, building on a recent partnership with 1Password for credential handling.

Meta rolls out consumer AI agent that can shop and send emails

Meta has introduced a new personal AI agent aimed at everyday users, capable of handling tasks like online shopping and sending emails. The launch is framed as an accessible entry point into agentic AI rather than a developer-focused tool.

Anthropic's Gmail connector lets Claude draft and send emails on any plan

Anthropic has released a Gmail connector that lets its Claude AI assistant read, draft, organize and send emails directly from a user's inbox. The feature works through natural-language requests rather than fixed commands, and is available to all Claude users regardless of whether they pay for a subscription.