OpenEFA Daily Threat Brief

October 10, 2026
SANS Threat Level: GREEN

Email Security Overview

1,639
Processed
788
Delivered
352
Quarantined
0
Rejected
21.5%
Block Rate
28.7
Avg Score

Threats Blocked by Category

352
Phishing
351
BEC
352
Impersonation
4
Backscatter

Top Spam Origin Countries

CountryBlockedShare
United States (US)24278.1%
The Netherlands (NL)3310.6%
United Kingdom (GB)237.4%
India (IN)82.6%
Singapore (SG)41.3%

Based on emails that reached the content filter. MTA-level blocks (RBL, GeoIP) are not included.

Top Spam Sender Domains

DomainBlockedAvg ScoreVolume
gmail.com1440.9
kbra.com12-0.3
jjgsxc.com891.0
dmarc.yahoo.com5-0.3
outlook.com533.6
cloudcontactai.org428.2
llc1.hkinvests.com348.4
snap5.snaptobook.com339.8

Notable High-Score Threats

ScoreSenderSubject
241.915Voicemail Service <tdupuis@[redacted].cmew voicemail received
230.85Voicemail Service <accounting@troycapitamew voicemail received
148.486Netflix Bonus Gift <support@airportcharlClaim Your LEGO Racing Car Bonus
138.066Netflix Member Reward <support@betting-c[[redacted]: New Sender] Your Racing Gift Is Ready
137.736United Airlines Loyalty Team <support@ve[[redacted]: New Sender] United Airlines Wants to Hea

CISA Known Exploited Vulnerabilities (New)

CVEVendor / ProductRansomware
CVE-2015-5477ISC BIND
ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries.
Unknown
CVE-2016-3081Apache Struts
Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.
Unknown
CVE-2023-22894Strapi Strapi
Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution.
Unknown
CVE-2021-3199ONLYOFFICE Docs
ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution.
Unknown
CVE-2015-3306ProFTPD ProFTPD
ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
Unknown

Active Malicious URLs (URLhaus)

50
Active URLs
1
Threat Types
1
Unique Hosts

Top threat types:

unknown: 50

Email Threat IOCs (ThreatFox)

20 email-related indicators of compromise in the last 24 hours.

Malware FamilyIOCsSeverity
Vidar16High
XWorm2Medium
AsyncRAT2Medium