28 Aug Security Report – 28 Aug 2026
Cybercriminals are increasingly exploiting trusted file formats such as SVG images to bypass email security controls and deliver phishing attacks. A recent campaign targeted more than 5,500 organisations with over 26,000 fake voicemail emails containing malicious SVG attachments that hid obfuscated JavaScript code. When opened, these files contacted attacker-controlled servers and typically directed users to credential-harvesting websites impersonating services such as Microsoft 365. The campaign also used sender spoofing, MIME-type manipulation, and personalised subject lines to increase its effectiveness, highlighting the growing trend of attackers leveraging seemingly harmless file types to evade traditional security defenses. Organisations should remain vigilant, treat SVG attachments as potentially executable content, and exercise caution when receiving unexpected voicemail or attachment-based notifications.
Recent Breaches
United States – Microsoft 365 –Technology
Exploit: Phishing
Risk to Business: Moderate: A sophisticated phishing campaign is using the Greatness phishing-as-a-service (PhaaS) platform to target Microsoft 365 accounts by impersonating RingCentral notifications. Greatness is a subscription-based PhaaS platform that has been active since at least 2022, providing cybercriminals with ready-to-use phishing toolkits. The platform has now expanded beyond credential phishing to adversary-in-the-middle (AiTM) attacks and device-code phishing targeting Microsoft 365 accounts. In a recent campaign observed by researchers, Greatness operators are abusing the RingCentral communications platform to bypass recipients’ email security filters. Attackers impersonate RingCentral by claiming messages originate from service@ringcentral[.]com and target actual users of the service with fake voicemail and performance-review notifications designed to entice them to open the emails. Although the messages originate from an unknown IONOS mail server, fail SPF and DMARC checks and lack a DKIM signature, they are still accepted by receiving systems because RingCentral is whitelisted. The emails also include a fraudulent banner claiming the sender has been verified through the organisation’s safe-sender list, further reducing suspicion and making the phishing messages appear more credible to recipients.
Europe –Swiss Federal Administrationl – Government & Public Sector
Exploit: Misconfiguration
Risk to Business: Moderate: The federal administration of Switzerland confirmed that more than 200 accounts were compromised in a data breach after attackers exploited a vulnerability in Microsoft SharePoint. Attackers breached SharePoint servers operated by Switzerland’s Federal Office for Information Technology and Telecommunication (FOITT) and stole login credentials associated with roughly 200 accounts. The servers were operated by FOITT within the federal government’s own data centers. According to the federal administration, unknown attackers exploited an unpatched SharePoint vulnerability to compromise the user and technical accounts. As a precautionary measure, FOITT is reinstalling the affected SharePoint servers. Internet access for external users remains blocked until the work is completed.
Talk to a TCT team member today about automation for your business.
Robert Brown
28/8/2026
Related Articles:
Build Cybersecurity Supply Chain Resilience
Are Passkeys Safer Than Passwords?