OpenEFA Daily Threat Brief

August 27, 2026
SANS Threat Level: GREEN

Email Security Overview

2,310
Processed
878
Delivered
602
Quarantined
0
Rejected
26.1%
Block Rate
38.5
Avg Score

Threats Blocked by Category

600
Phishing
597
BEC
602
Impersonation
15
Backscatter

Top Spam Origin Countries

CountryBlockedShare
United States (US)40484.5%
United Kingdom (GB)245.0%
The Netherlands (NL)214.4%
India (IN)204.2%
China (CN)91.9%

Based on emails that reached the content filter. MTA-level blocks (RBL, GeoIP) are not included.

Top Spam Sender Domains

DomainBlockedAvg ScoreVolume
gmail.com2157.5
emails.subway.com1933.0
kbra.com1111.9
justandfreegop.com1065.8
outlook.com860.0
netflir.com744.5
onedaystl.com750.3
thesixfigurecoach.com678.6

Notable High-Score Threats

ScoreSenderSubject
161.836"Anthem Blue Cross [redacted] -[[redacted]: New Sender] You've received an encrypted
156.25office ShareDocs Team <belinfo@jetro.go.[[redacted]: New Sender] Re: Online Statement & Ref A
156.134" [redacted]-Cpanel Webmail UsYour web domain email has expired - adv@sadefensej
156.134" [redacted]-Cpanel Webmail UsYour web domain email has expired - office@sadefen
156.134" [redacted]-Cpanel Webmail UsYour web domain email has expired - office@sadefen

CISA Known Exploited Vulnerabilities (New)

CVEVendor / ProductRansomware
CVE-2021-23758Ajax.NET Professional Ajax.NET Professional
Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
Unknown
CVE-2015-3246Red Hat Libuser
Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.
Unknown
CVE-2015-5287Red Hat Automatic Bug Reporting Tool
Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
Unknown
CVE-2022-0995Linux Kernel
Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.
Unknown
CVE-2026-8452Citrix NetScaler ADC and NetScaler Gateway
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.
Unknown
CVE-2019-1068Microsoft SQL Server
Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
Unknown
CVE-2026-60004Gitea Gitea
Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.
Unknown

Active Malicious URLs (URLhaus)

50
Active URLs
1
Threat Types
1
Unique Hosts

Top threat types:

unknown: 50

Email Threat IOCs (ThreatFox)

20 email-related indicators of compromise in the last 24 hours.

Malware FamilyIOCsSeverity
AsyncRAT6High
Remvio6High
Vidar4Medium
XWorm2Medium
Stealc1Low
HypeAgent1Low