惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Apple Machine Learning Research
Apple Machine Learning Research
S
Schneier on Security
P
Proofpoint News Feed
The Cloudflare Blog
S
SegmentFault 最新的问题
WordPress大学
WordPress大学
Hugging Face - Blog
Hugging Face - Blog
雷峰网
雷峰网
博客园 - 【当耐特】
博客园 - 叶小钗
大猫的无限游戏
大猫的无限游戏
F
Fortinet All Blogs
宝玉的分享
宝玉的分享
博客园 - 聂微东
Engineering at Meta
Engineering at Meta
G
Google Developers Blog
Know Your Adversary
Know Your Adversary
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
S
Securelist
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
C
CXSECURITY Database RSS Feed - CXSecurity.com
G
GRAHAM CLULEY
T
Threatpost
T
Threat Research - Cisco Blogs
酷 壳 – CoolShell
酷 壳 – CoolShell
C
Cisco Blogs
Cisco Talos Blog
Cisco Talos Blog
Latest news
Latest news
C
Cybersecurity and Infrastructure Security Agency CISA
L
LINUX DO - 热门话题
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
SecWiki News
SecWiki News
L
LangChain Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
The Last Watchdog
The Last Watchdog
阮一峰的网络日志
阮一峰的网络日志
Security Latest
Security Latest
P
Palo Alto Networks Blog
L
LINUX DO - 最新话题
博客园 - 司徒正美
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
P
Privacy International News Feed
N
News and Events Feed by Topic
Spread Privacy
Spread Privacy
T
Tenable Blog
有赞技术团队
有赞技术团队
MyScale Blog
MyScale Blog
aimingoo的专栏
aimingoo的专栏
AI
AI

Human Risk Management Blog

Report: Social Engineering Remains a Central Part of AI-assisted Attacks ClickFix Social Engineering is Now the Leading Malware Delivery Method CyberheistNews Vol 16 #28 Your 2026 Phishing by Industry Benchmarks: The Findings on Human Risk Scammers Can Use AI Tools to Pinpoint Your Location Based on a Photo Report: Attackers Are Using AI to Automate Social Engineering Your KnowBe4 Fresh Compliance Plus Content Updates from June 2026 From Awareness to Digital Workforce Security Your KnowBe4 Fresh Content Updates from June 2026 Threat Actor Uses Phishing to Breach Orgs for Ransomware Gangs Invoice Phishing Attacks Are Abusing the Shop App Phishing Campaign Impersonates Interpol to Deliver Ransomware Prompt Injection and the Rise of Agentic Risk Hyper-Targeted Social Engineering Needs Real-Time Video Response Your Email is Protected. Is Your Teams Chat? CyberheistNews Vol 16 #27 [HOW TO] Your Cybersecurity Starts at Home on World Social Media Day 2026 Phishing by Industry Benchmarking Report: Findings on Human Risk Static DLP Is Leaving You in the Dark: Why It’s Time for Intelligent, Self-Serve Outbound DLP and Misdirected Content Analysis INC Ransomware Gang Targets the Legal Sector 5 Essential Cybersecurity Defenses for Cloud Email Security Cybercriminals Are Targeting the FIFA World Cup 2026 Why Bite-Sized Security Awareness Training Matters in an Age of TikTok and Digital Distraction Happy 3rd Birthday to Our KnowBe4 Community! Phishing Exposes Employee Data at 86% of Fortune 100 Companies Shadow AI Is Not Shadow IT With a Better Marketing Budget CyberheistNews Vol 16 #26 A New Extortion Scam Uses IT Impersonation to Breach Organizations Cybersecurity Starts At Home This World Social Media Day FTC Report: Americans Lost $3.5 Billion to Imposter Scams Last Year Report: Device Code Phishing is Surging Report: Online Shoppers Increasingly Ignore Scam Warning Signs Security Training Needs Google Maps, Not Christopher Columbus Turn Account Takeover Into Real-Time Security Coaching Extortion Gang Sends In-Person Attackers to Exfiltrate Data Attackers aren’t loyal to any collaboration channel CyberheistNews Vol 16 #25 [The AI Tell] How To Expose Machine-Written Phishing Fast Social Engineering Attacks Abuse Workplace Collaboration Tools New Extortion Brand Uses IT Impersonation to Breach Organizations APWG Report: Social Media Phishing is Surging Cybersecurity Awareness Training for AI: Key Focus Areas Americans Lost $900 Million to AI-Powered Scams Last Year What AI Can’t Hide When It Writes a Phishing Email Your AI Agents Are Eager to Please And Easy to Exploit From 1% to 26%: How AIDA Orchestration Fixes the Remedial Training Gap Best AI Agent Security Tools for SMB and Enterprise in 2026 4 Hot Summer Travel Tips To Avoid Scams CyberheistNews Vol 16 #24 [FBI Alert] Lock Down Your Microsoft 365 Device Code Flows Now The Role of Agentic AI in Phishing Security Training A Credit Score for Cyber Behavior Agentic AI Security in 2026: What to Know How to Secure AI Agents: 4 Best Practices An Overview of Email Compliance Regulations and Reporting Report: AI-Assisted Fraud is Surging Attackers Use Spoofed ChatGPT Site to Deliver Malware I Love Device-Bound Session Credentials, But They Are Still Phishable and Hackable Nearly Two-Thirds of CEOs Cite Cyberattacks as Their Top Concern A Look at Spam vs. Phishing: 4 Key Differences KnowBe4 Wins Multiple 2026 TrustRadius Top Rated Awards Cyber Insurance for Mid‑Market Organizations in Southeast Asia KnowBe4 Earns Multiple 2026 Buyer's Choice Awards from TrustRadius The New Frontier: Securing Japan’s Hybrid Digital Workforce (2026 & Beyond) CyberheistNews Vol 16 #23 Now Phishing Attacks Use Real Hotel Reservations to Target Travelers Report: AI-Enabled Social Engineering Attacks Are on the Rise Your KnowBe4 Fresh Compliance Plus Content Updates from May 2026 FBI: Kali365 Phishing Kit is Targeting Microsoft 365 Accounts KB4-CON - AI Is Everything How to Secure AI Adoption In Your Organization Your KnowBe4 Fresh Content Updates from May 2026 The Silent Invitation: A Deep Dive into Calendar Invite Phishing Cyber Insurance for Mid‑Market Organizations in Southeast Asia Chinese-Language Phishing Kits Are Growing More Advanced Phishing Attacks Are Using Real Hotel Reservation Info to Target Travelers Warning: Scammers are Exploiting Geopolitical Unrest Athletes Are Increasingly Targeted by Social Engineering Attacks AI Agent Governance Part 3 - Runtime Governance: The Hidden Performance Cost of Agentic AI AI Agent Governance Part 2 - What Good Looks Like: Governing AI Agents in Practice 8 Ways to Reduce False Positives in Email Security Ransomware Attacks Drive a Surge in Cyber Insurance Claims My Favorite 5 KnowBe4 Agents Perry Carpenter KB4-CON 2026 Q&A: Deepfakes & Deception Free Gift Fallacy: How Attackers Harvest Credit Cards via Fake Surveys When Global Conflict Becomes a Cyber Weapon: How Iran Tensions and Other Stressful Events Fuel Social Engineering Attacks CyberheistNews Vol 16 #21 [Heads Up] GitHub Breach Shows Developer Tools Are Social Engineering Targets Alert: Extortion Groups Are Using Phishing Kits to Automate Their Attacks Beyond the Chatbot: Why Your AI Agents are Your Newest (and Most Vulnerable) Colleagues Report: Adversarial Use of AI is Evolving
Trust, Verify, Protect: Modernizing Email Security for the Cloud
Dr. Kawin Boonyapredee · 2026-07-16 · via Human Risk Management Blog

CISO_Blog_KawinB_400x225Picture this: Your company just fell victim to a massive data breach. The culprit wasn't a sophisticated malware strain, a zero-day exploit, or a compromised firewall. It was a perfectly legitimate-looking login from a VP’s account, originating from an unrecognized IP address, requesting an urgent wire transfer via a spotless, text-only email.

In the modern threat landscape, attackers have realized something crucial: Why break in when you can just log in?

As organizations shift to the cloud, the line between email security and identity management has blurred entirely. Traditional email security is failing because it’s looking for bad files, while attackers are busy stealing good identities. Here is how cloud email security should work in a world dominated by identity-first attacks.

The Core Problem: The Legacy Email Security Mirage

For decades, Secure Email Gateways (SEGs) acted as the bouncers of the corporate network. They inspected incoming traffic at the perimeter, checking for known bad signatures, malicious attachments and sketchy URLs.

But in a cloud-first world (think Microsoft 365 and Google Workspace), the perimeter no longer exists.

Attackers use trusted infrastructure: Phishing pages are hosted on legitimate SharePoint or Google Drive links.

Payload-less attacks dominate: Business Email Compromise (BEC) and vendor email compromise often contain zero links and zero attachments. They rely purely on social engineering and identity impersonation.

The attack happens inside the house: If an attacker compromises a user's credentials via a session hijacking attack, they can send malicious emails internally. A traditional SEG will never even see it.

What is an Identity-First Attack?

Identity-first attacks target the human element and the authentication mechanisms protecting them. Instead of exploiting software vulnerabilities, they exploit trust. Common tactics include:

  • Session Hijacking / Cookie Theft: Bypassing Multi-Factor Authentication (MFA) by stealing active session tokens.
  • Credential Stuffing: Using leaked passwords across multiple platforms.
  • Lookalike Domains & Display Name Spoofing: Creating an email address that looks identical to a company executive or trusted vendor (e.g., ceo@cornpany.com instead of company.com).

The Blueprint for Modern Cloud Email Security

To survive a world of identity-first threats, email security can no longer operate in a silo. It must evolve from a perimeter filter into an integrated, identity-aware behavioral engine. Here is what that looks like in practice:

1. Moving from Gateways to API-Based Architecture

Modern email security must sit inside the cloud email provider via native APIs, not in front of it. API-based solutions have total visibility. They can scan internal-to-internal emails, analyze historical communication patterns and retroactively remediate threats even after they land in an inbox.

2. Establishing a Dynamic "Behavioral Baseline"

Instead of looking for what is bad, security tools must deeply understand what is normal. By integrating with identity providers (like Okta, Entra ID, or Ping Identity), an identity-first email security platform builds a baseline of user behavior:

  • What time does this user usually log in?
  • What devices and locations do they typically use?
  • Who do they normally communicate with, and what is their typical tone or writing style?

If an executive suddenly emails finance from a new IP address demanding a wire transfer using language they've never used before, the system should automatically flag it, even if the MFA check passed.

3. Continuous, Risk-Based Authentication

Authentication is not a one-time event at login. If a user’s email behavior suddenly shifts (e.g., they start mass-forwarding sensitive emails to an external address), the email security engine must feed this risk telemetry back to the Identity Provider (IdP). This triggers an automatic response, such as forcing a re-authentication prompt, step-up MFA or terminating the active session entirely.

4. Supply Chain and Vendor Risk Profiling

You might have world-class security, but what about your vendors? Attackers frequently compromise a third-party vendor and use their legitimate email accounts to launch attacks against you.

Modern email security must continuously map your organization's supply chain, analyzing the reputation and communication cadence of external partners to detect when a trusted vendor's identity has been hijacked.

The Path Forward: Zero Trust for the Inbox

Adopting an identity-first approach to email security means applying the core principles of Zero Trust: Never trust, always verify.

The Identity-First Security Mantra: Treat every email not just as a piece of data, but as an assertion of identity.

When your email security solution can instantly cross-reference the content of a message with the context of the identity sending it, the attacker’s playbook falls apart. It’s time to stop focusing purely on the perimeter and start securing the identities that define your business.