Security Bite: Why your inbox is still so bad at blocking malware and spam

Security Bite 9to5mac

Many people are not aware that there’s a clever buffer that exists before emails land in an inbox. It’s here that each piece of mail is scanned, ideally blocking anything malicious before it arrives. However, over the years, email providers (mainly Gmail) have instead put more focus on adding “warning labels” to mail containing links or attachments they suspect are up to no good. Akin to putting lipstick on a pig. Despite these efforts, a stagering 91% of all cyberattacks still originate from an inbox.

If you think Google, Apple, and Microsoft could be doing more, you’re right. So, why haven’t they?


9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.


First, let’s look at how bad things currently are.

In a previous edition of 9to5Mac Security Bite, I discussed a recent study by web browser security startup SquareX that revealed just how little companies are doing to block malicious attachments and protect users.

The team of researchers took several different types of malware samples, attached them to emails, and sent them through Proton Mail to addresses on iCloud Mail, Gmail, Outlook, Yahoo! Mail, and AOL, part of the Yahoo! group. Notably, if the emails were delivered successfully to the users, they might be vulnerable to any potential threat contained within those attachments.

The table below summarizes the results of sending 7 of the 100 malicious samples to the various email providers, indicating whether the malicious attachment was delivered. “If an email was undelivered, it is a sign that malware was detected when the email was being processed by the server,” according to the study from SquareX.

Table showing what malware samples passed which email provider’s scanners and were delivered successfully.
Image: SquareX

The dilemma

Investing in robust email security features may seem like the obvious critical part of protecting users. However, Ian Thornton-Trump, CISO with threat intelligence solutions firm Cyjax, told Forbes, “this is akin to asking the free Wi-Fi at a Starbucks why are they not blocking more or all cyber attacks.” He further explained that it’s tough to balance free and secure in the same sentence.

Thornton-Trump argues that adding advanced email security features “can be deeply problematic with false positives, which may involve the use of technical support resources to help or fix—that expense across millions of users on a free platform may be commercially untenable.”

Moreover, others argue that email providers are dragging their feet on something that could cost substantial resources and impact their bottom line. With the upcoming release of iOS 18, macOS 15, and others next week, I’m interested to see if Apple will integrate any AI security features into the Mail app that could analyze attachments and URLs in emails in real time, among other various things.

I’m curious to hear your thoughts. Please tell me you are not still using that AOL email account from grade school…

About Security Bite: Security Bite is a weekly security-focused column on 9to5Mac. Every week, Arin Waichulis delivers insights on data privacy, uncovers vulnerabilities, or sheds light on emerging threats within Apple’s vast ecosystem of over 2 billion active devices to help you still safe.

More in this series


Add 9to5Mac to your Google News feed. 

FTC: We use income earning auto affiliate links. More.

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
Sony LinkBuds este o pereche de căşti cu design complet diferit de predecesori; Oferă 17 ore autonomie thumbnail

Sony LinkBuds este o pereche de căşti cu design complet diferit de predecesori; Oferă 17 ore autonomie

Sony a prezentat în această săptămână căştile LinkBuds, cu care se abate de la abordarea de design a seriei XM şi trece la un design deschis. E vorba despre un design tip “open ring”, care creşte confortul şi permite trecerea sunetelor ambientale. Publicitate ⚡ -3% din preț pe QuickMobile dacă folosești cuponul: QUICK202 Aceste accesorii…
Read More
Scientists Capture Airborne Animal DNA for the First Time thumbnail

Scientists Capture Airborne Animal DNA for the First Time

But for many biologists, tracking mammals that move miles each day and are wary of humans can be nearly impossible. Enter eDNA. “If we want to restore ecosystems, we need to understand how our conservation actions influence threatened and endangered species. But to do that we need to be able to detect even the rarest,…
Read More
ENISA leans into EU-based clouds with draft cybersecurity label thumbnail

ENISA leans into EU-based clouds with draft cybersecurity label

Cloud services providers that aren't based in Europe — like the Big Three — may have to team up with a cloud that is operated and maintained from the EU if they want ENISA's stamp of approval for handling sensitive data. ENISA, the European Union's cybersecurity agency, is currently developing a cybersecurity certification scheme that aims
Read More
The TicWatch Pro 3 Ultra, GTH+ and GTH Pro feature advanced heart rate monitoring. thumbnail

The TicWatch Pro 3 Ultra, GTH+ and GTH Pro feature advanced heart rate monitoring.

มีรายงานออกมาว่าสมาร์ทวอทช์รุ่นใหม่ของทาง Mobvoi อย่างรุ่น TicWatch Pro 3 Ultra, GTH+ และ GTH Pro จะมาพร้อมฟีเจอร์สำหรับตรวจวัดอัตราการเต้นของหัวใจขั้นสูงMobvoi ได้ประกาศ TicWatch GTH ไปเมื่อต้นปีที่ผ่านมา โดยสมาร์ทวอทช์รุ่นนี้มาพร้อมฟีเจอร์สำหรับตรวจวัดอุณหภูมิของผิว ควบคู่ไปกับฟีเจอร์ด้านสุขภาพอื่น ๆ ด้วยรายงานล่าสุดเผยว่า Mobvoi กำลังเตรียมเปิดตัวสมาร์ทวอทช์รุ่นใหม่อย่าง TicWatch Pro 3 Ultra, GTH+ และ GTH Pro ที่มีข่าวลือว่าสมาร์ทวอทช์จะมาพร้อมฟีเจอร์ตรวจวัดอัตราการเต้นของหัวใจขั้นสูง โดยข้อมูลนี้ถูกค้นพบในการแกะแอป APK เวอร์ชัน 4.3.0 ของทาง XDA Developersตามข้อมูลดูเหมือนว่าตัวฟีเจอร์นั้นจะมีความสามารถที่หลากหลาย ไม่ว่าจะเป็นการตรวจอายุทางชีวภาพของหัวใจ (Arterial Age), ความสามารถของหัวใจในการให้เลือดพร้อมออกซิเจนไปยังเซลล์ตามที่ร่างกายต้องการ (Exercise Capacity), ภาระในหัวใจจากการแข็งตัวของหลอดเลือดแดง (HSX) และวิธีการวัดอัตราการเต้นของหัวใจที่มีความแม่นยำเท่ากับวิธีการแบบ ECG มาตรฐาน (TruHR)ดูเหมือนว่าฟีเจอร์เหล่านี้จะได้รับความร่วมมือจากทาง AtCor Medical Inc บริษัทด้านการแพทย์ของออสเตรเลียซึ่งเป็นบริษัทในเครือของ CardieX…
Read More
Three ways to upgrade Windows 11 for free, with link to upgrade immediately!!! thumbnail

Three ways to upgrade Windows 11 for free, with link to upgrade immediately!!!

目前微軟的 Windows 10 已經開始免費提供升級到 Windows 11 的服務,只不過該服務當下主要面向於搭載 Windows 10 的新裝置,其餘符合條件的裝置會在後續陸續提供升級資源。Windows 11 系統對於硬件的要求頗高,所以導致了運行 Windows 10 系統的裝置不一定可以升級為 Windows 11。官方給出的升級條件是裝置需要搭載 Intel 第八代 Coffee Lake 或 AMD Zen 2 處理器及以上,支援 TPM 2.0,至少配備 4GB RAM+64GB ROM。官方給出的條件較為苛刻,導致數百萬台電腦無法正式升級到 Windows 11。有困難就有方法去克服,網上肯定會有第三方的其他升級方式。微軟的 Windows 11 系統採用逐步推出的形式來讓裝置進行升級,這意味著免費升級服務不會提供給所有現有符合條件的電腦。微軟的說法為,現有符合審升級條件的裝置應該會在 2022年中期前獲得 Windows 11 的升級。目前升級Windows 11系統主要有三種方式。第一種方法為 Windows 11 安裝助手,該方式是最佳最方便的升級方式,只需下載安裝助手,軟件會進行硬件檢測,當裝置符合要求便會選擇合適的升級的版本和語種開始下載和進入安裝程式。下載網址:https://go.microsoft.com/fwlink/?linkid=2171764第二種方法為創建 Windows 11 安裝媒體。先下載媒體創建工具,然後通過工具來製作可引導的 USB 或 DVD,最後創建本地安裝媒介便可多次使用進行升級無需再次進行下載過程。下載網址:https://go.microsoft.com/fwlink/?linkid=2156295第三種方法為下載 Windows 11 映像(ISO)檔。該方式較為複雜,需要創建可引導安裝媒體(USB、DVD)或創建虛擬機(.ISO 文件),用來安裝 Windows…
Read More
‎OPPO A54s will arrive in Europe with prices around €250 thumbnail

‎OPPO A54s will arrive in Europe with prices around €250

O conhecido leaker ‎‎Sudhanshu Ambhore‎‎ uniu-se ao ‎‎MySmartPrice‎‎ para partilhar algumas informações sobre o OPPO A54s. Este smartphone de gama de entrada da marca estará a caminho da Europa nos próximos dias.‎ ‎Diz-se que a OPPO vai lançar um novo smartphone na Europa chamado OPPO A54s. Espera-se que este dispositivo seja uma nova variante do…
Read More
Index Of News