
A significant security flaw in Proofpoint's email routing system has been exploited, allowing scammers to send millions of spoofed phishing emails that appear to originate from major brands such as IBM, Nike, and Disney. This vulnerability has raised concerns among users as the phishing campaign reportedly bypassed Proofpoint's security measures, impacting millions of individuals. The issue was first highlighted on July 29, 2024, and further discussions have emerged about the implications of the flaw, including the potential weaponization of Microsoft Outlook through a tool named Specula, which utilizes a registry value to enable command and control operations within the email client. This development poses a new threat to email users as security experts continue to analyze the ramifications of these vulnerabilities.
Specula Tool Weaponizes Microsoft Outlook Vulnerability: New Threat for Email Users https://t.co/NRH1BT2z83
Specula : Turning Outlook into a C2 client with a single registry value and the release of a new C2 framework : https://t.co/KpXjImL45M credits @Oddvarmoe @freefirex2 Specula is a framework that allows for interactive operations of an implant that runs purely in the context…
Millions of Spoofed Emails Bypass Proofpoint Security in Phishing Campaign https://t.co/XLgRFxYGiI

