Issue 4 | July 2026
This month: Over 13,000 New Jersey hospital patient records exposed, Instagram’s controversial AI tool draws criticism, and discover what our team learned at Unify 2026 in Austin, Texas.
Plus: What is ghost phishing? Learn how attackers are using a malicious kit to bypass email security detection and sneak into Microsoft 365 accounts without users ever exposing their passwords. Is your organization at risk?
Recent News: The Latest from the Digital Trust Landscape
2026’s Top Cybersecurity Breaches of 2026 – From gaming giants to healthcare providers, this year’s worst cybersecurity incidents show that no industry is off limits. See which breaches made the list and what they mean for your own risk exposure. Full story
Law Firm Breach Exposes Hospital Records for 13K Patients – A cyberattack on a New Jersey law firm representing some of the state’s largest hospitals exposed data from nearly 13,000 patients, a reminder that sensitive medical information flows through more than just healthcare organizations. See what happened, and what it means for anyone whose provider relies on third-party vendors. Full story
Employees Driving Cybersecurity Risk as Shadow AI Surges – A new WatchGuard survey finds 64% of employees admit to using unauthorized AI tools for work. At the same time, password reuse, public Wi-Fi, and VPN-free access to corporate resources remain widespread. See how your own daily habits stack up against the emerging risks security teams face every day. Full story
Instagram’s New AI Tool Sparks Backlash from Cybersecurity Experts – Instagram’s latest Muse Image tool lets anyone generate AI content from public account photos, and automatically opts users in unless they find the setting to turn it off. Cybersecurity researchers warn it could open the door to impersonation and phishing, while entertainment industry unions urge members to opt out. See what’s driving the pushback, and whether your own account is opted in without you realizing it. Full story
Free Tier C2PA Claim Signing Certificates – As the need for content authenticity intensifies with emerging legislation and AI content disclosure mandates, C2PA certificates have become one of the most in-demand products in the trust space. Learn More
Industry Spotlight: Practical Solutions for Real-World Challenges
The Phishing Email That Looks Legit Until It’s Too Late
A campaign called EvilTokens is targeting businesses across the US and Europe using a technique researchers call “ghost phishing.” The malicious content remains hidden during email security inspection and is only decrypted and rendered in the victim’s browser. By the time it becomes visible, the damage is already in motion.
The kit uses Microsoft Device Code Phishing to walk victims through what appears to be a legitimate Microsoft login flow, thereby unknowingly authorizing attackers to their Microsoft 365 accounts without ever exposing a password. Traditional URL scanning and network-level controls capture only the encrypted response, not what the employee actually sees.
The business impact: Based on sandbox submission data from 15,000 organizations, phishing exposure in 2026 reached 75.6% in consulting, 72.8% in financial services, 71.9% in manufacturing, and 67.9% in technology.
A single compromised Microsoft 365 account opens the door to corporate email, files, cloud services, and connected infrastructure. Because the attack bypasses the inspection layer entirely, security teams are left making containment decisions without complete evidence, consequently extending the exposure window and escalating incident costs.
What would have prevented it: Ghost phishing works because the email itself appears legitimate and the malicious payload never reveals itself to scanning tools, but it does have an Achilles heel: It cannot forge a trusted digital signature.
SSL’s S/MIME certificates cryptographically bind an email to a verified sender identity, providing a crucial layer of trust. An employee receiving a phishing email from an unverified or unsigned sender has a visible, actionable signal that something is wrong, before any link is clicked and before any browser renders anything. For organizations where Microsoft 365 access is a high-value target, S/MIME is a front-line control that operates independently of URL inspection and survives exactly the kind of evasion this campaign was designed to achieve.
The broader lesson: Modern phishing no longer reveals itself fully in the email or the initial URL response. Attackers are now building attacks that are specifically designed to pass inspection and detonate later. The security controls that organizations have relied on for years are being engineered around, not broken. The answer is not faster scanning of the same signals. It is adding layers of trust verification that operate before the link is ever clicked, at the identity level, where evasion is substantially harder.
Source:
https://thehackernews.com/2026/07/new-ghost-phishing-wave-is-breaking.html
Past and Upcoming Events: Conferences, Standards Meetings, and more
Learnings from Unify 2026
Team SSL headed to Austin, Texas, from June 16-18, for Unify 2026, hosted by the Connectivity Standards Alliance (CSA). With over 300 attendees and 50 speakers from around the world, the conference featured more than 20 sessions over two days.
“Matter adoption has accelerated significantly in recent years,” says Dom Guinard, SSL Director of Product – Content Authenticity and IoT. “Interoperability is vital for all users, and that’s essentially what Matter is about: creating the application layer for the smart home, for the Internet of Things (IoT), and making all of these devices work together.”
To hear more about the event, including thoughts from Leo Grove, President and CEO, read the full recap here.
EU Artificial Intelligence Act Article 50
Starting August 2, 2026, any organization that builds or deploys generative AI systems that reach people in the EU has a new legal duty: it must disclose that the content is AI-generated. Learn more about the regulation here.
Quick Links: Guides, Articles, and Industry Resources
- How to Configure SSL.com S/MIME Certificates for MS Outlook on iOS and Android — Learn how to deploy SSL.com S/MIME certificates to Microsoft Outlook for iOS and Android using manual installation or Intune for secure email signing and encryption.
- Getting Started with Your SSL Account — New to SSL? Learn how to navigate the SSL.com Customer Portal to manage certificate orders, complete validations, download certificates, and streamline lifecycle management.
- Private PKI FAQs: 8 Common Questions Answered — Get answers to the 8 most common Private PKI questions, from dedicated CA hierarchies and HSM key protection to WebTrust audits and automation protocols.
- How to Submit to the C2PA Conformance Program — Learn the technical steps to submit your product to the C2PA Conformance Program and obtain a Claim Signing Certificate from SSL.
Have questions about any of these topics or want to discuss your digital trust solutions with our experts? Reach out to us below:
