OpenEFA Daily Threat Brief

May 09, 2026
SANS Threat Level: GREEN

Email Security Overview

2,004
Processed
1,519
Delivered
337
Quarantined
0
Rejected
16.8%
Block Rate
16.2
Avg Score

Threats Blocked by Category

337
Phishing
334
BEC
337
Impersonation
40
Backscatter

Top Spam Origin Countries

CountryBlockedShare
United States (US)19873.9%
Germany (DE)2710.1%
India (IN)238.6%
China (CN)134.9%
The Netherlands (NL)72.6%

Based on emails that reached the content filter. MTA-level blocks (RBL, GeoIP) are not included.

Top Spam Sender Domains

DomainBlockedAvg ScoreVolume
gmail.com2350.9
hes.it1171.8
kerilourtie.com645.5
algurabinvestment.org691.9
outlook.com560.8
em.1800flowers.com440.7
papeleriaomega.com.mx477.7
capital.net4145.2

Notable High-Score Threats

ScoreSenderSubject
225.267Costco Special Note <costcospecialnote@mC0STC0's Membership update and what you need to kn
189.775 American Express | Customer Care <cco@Your account has been placed on temporary hold
185.134"[redacted]" <qr11@lifecf.org>[[redacted]: New Sender] Security Notice: Unauthorize
183.775 American Express | Customer Care <cco@Your account has been placed on temporary hold
160.252 American Express | Customer Care <Cust[[redacted]: New Sender] Your account has been placed

CISA Known Exploited Vulnerabilities (New)

CVEVendor / ProductRansomware
CVE-2026-42208BerriAI LiteLLM
BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorised access to the proxy and the credentials it manages.
Unknown
CVE-2026-6973Ivanti Endpoint Manager Mobile (EPMM)
Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.
Unknown

Active Malicious URLs (URLhaus)

50
Active URLs
1
Threat Types
1
Unique Hosts

Top threat types:

unknown: 50

Email Threat IOCs (ThreatFox)

20 email-related indicators of compromise in the last 24 hours.

Malware FamilyIOCsSeverity
Remvio13High
AsyncRAT5High
Vidar2Medium