BI.ZONE Mail Security 3.0 Enhances Detection of Password-Protected Archives and Spam Variants
BI.ZONE has released Mail Security 3.0, adding new detection mechanisms for email threats and expanded administrative capabilities. The solution now pays closer attention to password-protected archives, verifies sender authenticity, and identifies mass mailings in which attackers make minor text changes to bypass filters.
When the contents of a password-protected archive, including nested files, cannot be extracted, the system assigns additional risk points to the message. The archive itself is not automatically marked as malicious, but it loses its previous immunity simply because its contents are locked. This approach allows analysts to investigate suspicious encrypted attachments without false negatives caused by encryption.
A second new method compares message texts and detects series of nearly identical emails. BI.ZONE uses this technique to uncover spam campaigns where threat actors rearrange a few words in an attempt to evade detection. Delivery rules can now take into account the results of SPF and DKIM checks, helping to separate legitimate senders from those who spoof familiar names to steal credentials.
According to BI.ZONE statistics, phishing accounted for 90 percent of illegitimate email traffic in the first half of 2026. Protection for administrative accounts has been strengthened with a mechanism against automated password brute-force attacks. After a defined number of failed login attempts, users must complete a CAPTCHA challenge.
Administrators can now enable, disable, or delete rules in bulk, download quick rules as a group, and perform operations on multiple messages simultaneously. The updated journal displays message information in a side panel, while a new Events section alerts users to important changes and upcoming license expiration. User activity logs can be forwarded to external monitoring and SIEM systems via Syslog.
Related articles
Fake GTA and Ghost Casino Apps Flood Google Play Early Access with Scam Promises
Unscrupulous developers are exploiting Google Play's Early Access program to distribute applications that make false promises of earnings through fake games and casino experiences. These apps lack public ratings and reviews, preventing disappointed users from warning others before installation. Bitdefender reports that the scheme is heavily promoted via advertisements on TikTok, Facebook, and other social networks, often featuring deepfakes of actors, athletes, and celebrities to build credibility. Users are lured with offers of PayPal payments, cryptocurrency, gift cards, and casino jackpots, but the apps deliberately slow progress near withdrawal thresholds. After installation, the software displays generous virtual winnings that never translate into real payouts. The campaign relies on aggressive advertising and misleading interfaces to maximize installations before users realize the fraud.
F6 and MAX Neutralize Over 2,550 External Phishing and Scam Resources in Two-Month Operation
F6 and the MAX messenger have jointly blocked more than 2,550 malicious external websites used for phishing, scams, and other forms of online fraud. The effort relied on the F6 Digital Risk Protection platform, which continuously scans for fake authentication pages and fraudulent resources targeting users. Monitoring took place during July and August 2026, after which experts from both organizations arranged for the sites to be taken down. The action focused exclusively on external resources and did not involve any malicious content hosted inside the MAX messenger itself. F6 Digital Risk Protection head Stanislav Goncharov noted that regular takedowns can reduce attacker activity over time, yet users must still verify website addresses manually before entering credentials or payment data.
Trezor Warns of Email Provider Breach Used in Targeted Phishing Campaign Against Hardware Wallet Users
Trezor has disclosed that attackers compromised an external email provider and leveraged it to send phishing messages that appeared to originate from the company. The emails carried the subject line 'Critical Security Alert: STM32 Entropy Vulnerability' and falsely claimed a hardware flaw in STM32 microcontrollers that would reduce entropy and allow seed phrase reconstruction. No such CVE exists, and the campaign followed classic social-engineering patterns of urgency and brand impersonation aimed at stealing recovery phrases. Trezor has since disabled the malicious domain and continues investigating how the provider was accessed. Similar messages may have reached users of BitBox, suggesting possible compromise of shared service providers across the hardware wallet ecosystem. The incident underscores the difficulty of detecting phishing when it originates from legitimate third-party infrastructure.
Free Robux Lures Used in Phishing Campaign Targeting Children's Messenger Accounts
Scammers have launched a new wave of attacks aimed at children and teenagers by promising free in-game currency for Roblox, Brawl Stars, and Standoff 2. The scheme, uncovered by specialists from F6, uses short YouTube videos that direct victims to phishing sites disguised as reward platforms. One prominent site branded as NovaDrop tricks users into selecting a messenger and game before presenting a rigged roulette that awards a fake prize of 25,000 coins. To claim the reward, victims must enter a phone number and six-digit verification code, which actually authorizes the attackers in the chosen messenger. Once inside, the criminals can read conversations, view documents and media, access contacts, and send messages to the victim's friends while sometimes remaining undetected. The attackers are increasingly focused on hijacking existing accounts due to difficulties in purchasing new Russian profiles for their operations.