Signal & Noise, Volume 7
by Brendan DeWyse on Aug 21, 2026
Attackers Are Getting Smarter: Don't Rely on Reputation Alone
A phishing campaign reached ten of our client tenants this month without spoofing a single sender, compromising a single account, or registering a single new domain. Every reputation check it passed, it passed honestly.
An attacker signed up for a trial account on a legitimate, well-established educational CRM, then used that platform's own notification system to send phishing at scale. No spoofing. No compromise. Every reputation check on the way in came back clean, because the sending infrastructure genuinely is legitimate.
The Account
A free trial on a real education platform. No stolen credentials, no compromised mailbox. Just a signup form and a card.
The Sender
Mail leaves through the platform's own notification system, inheriting a clean shared sending reputation the attacker did nothing to earn.
The Link
A payload domain roughly a decade old per DNS and WHOIS. Too boring for newly-registered-domain scoring to flag.
The Tell
Subject lines personalized per company. Ten tenants, 47 recipients. This was aimed, not blasted.
Why There's No Clean Block
The sender domain is legitimate shared infrastructure and the sending IPs sit in a shared mail-provider pool. Block either one and unrelated legitimate mail goes down with it.
Microsoft's own detection flagged the content independently as Phish, Malicious by fingerprint and URL reputation, and auto-quarantined a number of these after delivery. That native detection, plus client awareness, is the mitigation.
How It Passed Inspection
-
Legitimate sender
Real Saas platform, real notification system, nothing spoofed
-
Inherited reputation
A clean sending history the attacker rented rather than built
-
Aged domain
Roughly ten years of DNS and WHOIS history, so age scoring stayed quiet
-
Personalized subject
Written per company, not one template sprayed wide
-
Single-tenant blindness
Low-priority spam reports until somebody looked across all ten tenants
What Actually Caught It
The sender was real. The domain was old. The message was still a phish.
-
Cross-tenant view. Isolated, these were low-priority user-reported spam tickets. Correlated, they're one campaign.
-
The ask, not the sender. Reputation said clean. What the message wanted did not.
-
Native quarantine. Microsoft's postdelivery detection did real work here. Let it run.
-
User reports. Every one of these started with somebody hitting the report button.
Why This Matters
Reputation is a measure of history, not intent. A platform that has sent legitimate mail for years keeps its clean record on the day an attacker rents ten minutes of it. Filters score the infrastructure. They do not score the ask.
You are not expected to audit sender infrastructure. You are expected to notice when a message you did not ask for wants you to log in somewhere. Report it, and let us do the correlating. Looked at one inbox at a time, this never rises above the noise.
This Week in Cyber History
AUG 19, 2003 • SOBIG.F
At its peak, one in every 17 emails on the internet carried it. The worm harvested address books from infected machines and forged its sender line with names recipients already knew. It exploited nothing. It borrowed trust.
Meet the Analyst
Sarah Menne, SOC Analyst II
Sarah is a SOC Analyst II at RADICL. Before joining the team she spent nearly four years with the National Oceanic and Atmospheric Administration, starting as an IT intern responsible for hardware and applications across ships, aircraft, and ground facilities, along with user accounts, permissions, and access rights.
From there she stepped into an Information Technology Security Specialist role, monitoring and responding to threats across NOAA's systems and working with IT security and compliance teams on detection and escalation. Her path started earlier, in the U.S. Army, where she spent two years as a Signal Support Systems Specialist with postings in Texas, South Korea, and Georgia. That grounding still shows in how she works the floor today.
Case Spotlight
Clean to Scanners
A user clicked a link that every automated check called safe. Crawlers fetching the URL got a harmless redirect loop; live fetches from real devices landed on a credential-harvesting page, which sat open about 45 seconds. Nothing ran on the endpoint, and a 27-day sign-in review found no unfamiliar authentication. Credentials rotated, sessions revoked, infrastructure blocked.
Unsigned • Open Inquiry
A repackaged, unsigned build of a torrent client with logon persistence ran five days on a machine carrying the customer's EDR sensor. Detonation reached only the vendor's own infrastructure, and a tenant-wide sweep found the file nowhere else. The process was killed; the binary and its autostart entry remain. Whether the device is company issued or personal decides what happens next.
Benign • AI Tooling
A suspicious JavaScript alert on a developer workstation traced back to an Al coding assistant capturing a debug screenshot from its own scratch folder. Full process ancestry confirmed it, and nothing left the tool's working directory. Closed benign. Even the robots helping write code can set off alarms built to catch actual bad guys.
Eye on the Threatscape
01 The Exploit Script Wrote Itself
Five federal agencies issued a joint advisory on Aug 19 warning that attackers are using Al-generated exploitation scripts, dressed up as legitimate OT monitoring tools, against internet exposed Siemens S7 controllers. The advisory names the Defense Industrial Base among the sectors that could be hit. Their words, not ours: "This is not a theoretical risk." Al didn't invent the attack. It removed the expertise it used to require.
02 Your Org Chart, For Sale
A threat actor is selling employee directories pulled straight out of nine large companies' Microsoft Entra tenants, roughly 3.6 million records. No Azure flaw was involved. Researchers tie the access to credentials harvested by infostealer malware on employee machines. The dumps include job titles, service accounts, and admin identities, which is a target list for the next phishing round.
03 The VPN That Watches
Researchers linked 737 free VPN and proxy extensions in the Chrome Web Store to a single operation, 274 of them impersonating names like NordVPN, Proton VPN, and ExpressVPN. Once connected, they route the entire browser session through the operator's own proxy servers. Google pulled some; hundreds stayed listed. Worth an extension inventory on managed devices.
vSOC Tip of the Week
If an email asks you to sign in, don't use the link to get there. Open the site the way you normally would, by bookmark or by typing the address, and see whether the same thing is waiting for you. If it isn't, send us the email.
Prefer this newsletter as a PDF? Download it here.
- DIB Innovators (129)
- Podcast (128)
- Industry Analysis (104)
- Threat Hunting and Intelligence (28)
- Regulatory Compliance (24)
- Attack Surface and Vulnerability Management (15)
- CMMC (14)
- Zero Gravity Summit (11)
- General (6)
- Signal & Noise (6)
- Company (5)
- Security Operations & vSOC (5)
- Testimonials (5)
- Founder (4)
- Incident Response (3)
- Managed Security Operations (3)
- Operational Resilience (2)
- Threat Management (1)
- Webinar (1)
You May Also Like
These Related Stories

EP 102 — Vendra's Shan Mohta On Going From 200 Investor Rejections To Parts Orbiting Earth

EP 4 - Parts Life's Sam Thevanayagam on Solving Obsolescence in the DIB


No Comments Yet
Let us know what you think