Your answer to phishing is awareness?

That might be enough when you're up against a Nigerian prince, but when you're up against a kobold, it won't be enough.

We've looked at an attack strategy that (mis)uses HTML and CSS to create sophisticated phishing attacks that will fool even the most attentive reader.

The only solution: deactivating HTML emails altogether.

https://lutrasecurity.com/en/articles/kobold-letters/

#email #htmlemails #phishing #KoboldLetters

Kobold letters – Lutra Security

Anyone who has had to deal with HTML emails on a technical level has probably reached the point where they wanted to quit their job or just set fire to all the mail clients due to their inconsistent implementations. But HTML emails are not just a source of frustration, they can also be a serious security risk.

@lutrasecurity Google announced, that they will fix the issue in Gmail (I already updated the article).