Re: [mailop] [STATE OF THE UNION] Tales from the Trenches..

2024-05-30 Thread Slavko via mailop
Dňa 30. mája 2024 19:56:01 UTC používateľ Michael Peddemors via mailop napísal: >However, it isn't as simple as blocking every IP that bangs on your door. If >you block large CGNAT IP's for instance, one compromised IoT device behind >that IP can stop hundreds of legitimate users. Yes, that

Re: [mailop] [STATE OF THE UNION] Tales from the Trenches..

2024-05-30 Thread Jarland Donnell via mailop
Possibly valuable attachments: - We saw an increase in compromised email accounts sending Comcast phishing emails which actually contained HTML that pulled valid Comcast assets into the emails. To the point that we have halted all outgoing mail containing those assets. This might correlate to

Re: [mailop] [STATE OF THE UNION] Tales from the Trenches..

2024-05-30 Thread Michael Peddemors via mailop
Great that you want/willing to share.. However, it isn't as simple as blocking every IP that bangs on your door. If you block large CGNAT IP's for instance, one compromised IoT device behind that IP can stop hundreds of legitimate users. Think about the Airports' WIFI.. Coffee Shops.. or Dyn

Re: [mailop] [STATE OF THE UNION] Tales from the Trenches..

2024-05-30 Thread Slavko via mailop
Dňa 30. mája 2024 18:23:25 UTC používateľ Michael Peddemors via mailop napísal: >I am sure there are many others that are dedicated to strictly AUTHentication >abuse.. The key is to be able to do the check at all levels of authentication, >whether by using an RBL, or static lists.. I hope, th

Re: [mailop] [STATE OF THE UNION] Tales from the Trenches..

2024-05-30 Thread Michael Peddemors via mailop
On 2024-05-30 10:46, Richard Laager via mailop wrote: On May 30, 2024, at 12:35, Michael Peddemors via mailop wrote: They do know there is RBL's that list known abusive BEC Attackers? I’m new to the list (though not email admin). What RBL are you saying I should be looking at? I already u

Re: [mailop] [STATE OF THE UNION] Tales from the Trenches..

2024-05-30 Thread Richard Laager via mailop
> On May 30, 2024, at 12:35, Michael Peddemors via mailop > wrote: > > They do know there is RBL's that list known abusive BEC Attackers? I’m new to the list (though not email admin). What RBL are you saying I should be looking at? I already use SpamHaus’s various lists and SpamCop. Thanks!

Re: [mailop] [STATE OF THE UNION] Tales from the Trenches..

2024-05-30 Thread Rob McEwen via mailop
>>AI and ChatGPT created malware campaigns has not really seen the light of day Regarding that, what I'm about to say is very anecdotal - and might be rare - but I'm seeing a distinct uptick in cold sales call spams sent to me - that obviously includes AI-generated targeted content. It's obvio

[mailop] [STATE OF THE UNION] Tales from the Trenches..

2024-05-30 Thread Michael Peddemors via mailop
Both life and Business have been very active, so it's been a bit since I posted one of these.. It's about time again.. * SendGrid continues to allow the same common threats from escaping * Increase in threat actors from Thailand/Vietnam region, but probably proxies for Chinese actors * Digital

[mailop] Microsoft failing to connect?

2024-05-30 Thread Dean Walsh via mailop
Hi All, We're seeing a weird issue with random servers on our network failing to connect from Microsoft. It's only some prefixes, and only seems to be affecting Microsoft. Is anyone else having this problem? I've been unable to have someone from Microsoft investigate further. Reason: [{LED=45

Re: [mailop] Scanner frequency ?

2024-05-30 Thread Matus UHLAR - fantomas via mailop
On 29.05.24 16:29, J Doe via mailop wrote: Has anyone noticed a recent increase in the frequency of scans of their mail servers by Censys ? I am seeing the following in my logs more often: May 29 01:49:13 server smtpd[50661]: 78d6ab67951b801a smtp connected address=199.45.154.4 host=sc