OpenEFA Daily Threat Brief

April 08, 2026
SANS Threat Level: GREEN

Email Security Overview

3,233
Processed
2,306
Delivered
438
Quarantined
0
Rejected
13.5%
Block Rate
19.5
Avg Score

Threats Blocked by Category

438
Phishing
435
BEC
438
Impersonation
34
Backscatter

Top Spam Origin Countries

CountryBlockedShare
United States (US)29884.2%
The Netherlands (NL)236.5%
Germany (DE)154.2%
Türkiye (TR)92.5%
India (IN)92.5%

Based on emails that reached the content filter. MTA-level blocks (RBL, GeoIP) are not included.

Top Spam Sender Domains

DomainBlockedAvg ScoreVolume
gmail.com2151.7
outlook.com1154.2
60minuteshealth.com751.9
fehrenbach-klaus.de799.6
hotmail.com571.7
fcchellas.gr565.9
gangyuege0927.com476.3
ezlynx.com420.2

Notable High-Score Threats

ScoreSenderSubject
183.853Apple <apple-co.jp-vzDS@ar.em-net.ne.jp>"Appleアカウントの安全性向上のためのご確認(No.-[-randomdate-])
183.55"Roundcube Support [redacted]" Resolve Delivery Failure
181.925"[redacted] Webmail" <randhir.kumar@velocustomer.care@[redacted]: Action required.
181.485"Mr.George" <marazzi.jacqueline1@vp.pl>[[redacted]: New Sender] Revert back..Chicago
181.438"[redacted] Webmail" <randhir.koffice@[redacted]: Action required.

CISA Known Exploited Vulnerabilities (New)

CVEVendor / ProductRansomware
CVE-2026-1340Ivanti Endpoint Manager Mobile (EPMM)
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
Unknown
CVE-2026-35616Fortinet FortiClient EMS
Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Unknown

Active Malicious URLs (URLhaus)

50
Active URLs
1
Threat Types
1
Unique Hosts

Top threat types:

unknown: 50

Email Threat IOCs (ThreatFox)

20 email-related indicators of compromise in the last 24 hours.

Malware FamilyIOCsSeverity
Vidar11High
AsyncRAT3Medium
XWorm3Medium
Remvio3Medium