OpenEFA Daily Threat Brief

August 26, 2026
SANS Threat Level: GREEN

Email Security Overview

2,219
Processed
947
Delivered
536
Quarantined
0
Rejected
24.2%
Block Rate
33.9
Avg Score

Threats Blocked by Category

536
Phishing
536
BEC
536
Impersonation
10
Backscatter

Top Spam Origin Countries

CountryBlockedShare
United States (US)35085.2%
United Kingdom (GB)235.6%
India (IN)153.6%
France (FR)122.9%
Canada (CA)112.7%

Based on emails that reached the content filter. MTA-level blocks (RBL, GeoIP) are not included.

Top Spam Sender Domains

DomainBlockedAvg ScoreVolume
gmail.com2052.4
outlook.com1054.3
emails.subway.com934.1
justandfreegop.com860.9
sendadate.com741.3
netflir.com745.3
jjansendesigns.com566.3
suncapitalfundings.com554.8

Notable High-Score Threats

ScoreSenderSubject
173.125cPanel Mail Support <sales@csamwexzatynn[[redacted]: New Sender] Pending Messages Require You
162.031American Express <rob@[redacted]>Complete adavance security measures to strengthen
159.741American Express Account Protection Ser[[redacted]: New Sender] Amex Fraud Alert: Please ver
157.834American Express <contact@[redacted].cComplete adavance security measures to strengthen
157.369 AT&T My Account <customer.care@[redacted].Payment was cancelled by card issuer - USER ID - c

CISA Known Exploited Vulnerabilities (New)

CVEVendor / ProductRansomware
CVE-2026-60004Gitea Gitea
Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.
Unknown
CVE-2026-21962Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.
Unknown

Active Malicious URLs (URLhaus)

50
Active URLs
1
Threat Types
1
Unique Hosts

Top threat types:

unknown: 50

Email Threat IOCs (ThreatFox)

20 email-related indicators of compromise in the last 24 hours.

Malware FamilyIOCsSeverity
AsyncRAT9High
Vidar5High
XWorm2Medium
Remvio2Medium
Lumma Stealer2Medium