Monday, June 22, 2026

Security Boulevard Logo

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Creators Network
    • Latest Posts
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming Webinars
    • Calendar View
    • On-Demand Webinars
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
    • Techstrong.tv Podcast
    • TechstrongTV - Twitch
  • Library
  • Related Sites
    • Techstrong Group
    • Cloud Native Now
    • DevOps.com
    • Security Boulevard
    • Techstrong Research
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • Devops Chat
    • DevOps Dozen
    • DevOps TV
  • Media Kit
  • About
    • Sponsor

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Cybersecurity Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches 

Home » Cybersecurity » StrongestLayer: Top ‘Trusted’ Platforms are Key Attack Surfaces

StrongestLayer: Top ‘Trusted’ Platforms are Key Attack Surfaces

by Adrian Bridgwater on February 2, 2026

There’s something of a renaissance happening in cybersecurity. No, it never went away, you’re right, but the level of vocal engagement coming out of every enterprise software vendor in this space now spans traditional anti-virus protection to network-level robustness controls and onward to (obviously) agentic AI lifecycles… and then leaps forward to the next era of optical photonics-based computing and, of course, quantum encryption.

Working in the here and now with a self-imposed remit to protect the most pressing cyber vulnerabilities is StrongestLayer. The company’s new threat intelligence report (jauntily named What Your Email Security Can’t See) is based on an analysis of 2,042 advanced email attacks that successfully bypassed Microsoft Defender E3/E5 and well-known secure email gateways before being detected. 

Quick, Hide Behind the Platform

The findings may point to a shift in attacker behavior, where adversaries increasingly hide behind well-known platforms such as DocuSign, Microsoft and Google Calendar, which are all services that organizations typically cannot block without disrupting operations.

Rather than relying on malware or obvious phishing techniques, today’s attackers exploit trust, authentication gaps, and operational dependency. The report provides rare visibility into the techniques that define modern email threats by examining only attacks that incumbent security controls missed.

“Email security has reached an inflection point,” said Alan LeFort, CEO and co-founder, StrongestLayer. “The controls enterprises depend on were designed to detect patterns and known bad signals. But attackers are now exploiting trusted brands and legitimate infrastructure, areas that those systems were never built to reason about.”

The company says that 77% of attacks failed Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), or Domain-based Message Authentication, Reporting, and Conformance (DMARC) authentication yet still reached inboxes, exposing a widespread enforcement gap. 100% of threats bypassed incumbent email security, including Microsoft E3/E5 and leading secure email gateways. Approximately 45% of attacks showed indicators of AI assistance, a figure projected to rise to 75–95% within the next 18 months

Trusted Brands, New Attack Surface

The report thinks that attackers are no longer trying to look legitimate – they are hiding behind platforms that already are. DocuSign alone accounted for more than one-fifth of all attacks analyzed, particularly targeting legal, financial and healthcare organizations where document-signing workflows are deeply embedded in daily operations.

Google Calendar attacks represent an especially concerning trend. Because calendar invitations are delivered via calendar APIs rather than email, these attacks bypass secure email gateways entirely, creating a blind spot for most security teams.

The Authentication Challenge

Email authentication is widely promoted as the solution to impersonation attacks, yet the data tells a more complex story. Most organizations maintain permissive DMARC policies to avoid blocking legitimate but misconfigured senders. Attackers knowingly exploit this reality, delivering messages that fail authentication but are still allowed through.

“StrongestLayer’s analysis shows AI-assisted phishing has fundamentally changed the economics of detection. Traditional phishing campaigns reuse templates with high similarity, allowing pattern-based systems to work. AI-generated attacks, however, share as little as 12–18% similarity across variants, rendering pattern matching mathematically ineffective – a phenomenon [our] report calls the Pattern-Matching Cliff. As AI-generated attacks become the default, organizations relying solely on pattern-based detection face a rapidly narrowing window to adapt,” explains LeFort and team

The attacks in this report share a common trait: they don’t look malicious in isolation. Legacy systems operate as “prosecutor-only” architectures, searching for evidence of guilt such as malicious links or known-bad indicators. What they lack is the ability to prove legitimacy – whether a DocuSign notification aligns with real business activity or a calendar invite reflects an authentic workflow.

Defending against trust-exploitation attacks requires a dual-evidence approach that evaluates both threat signals and business legitimacy signals, enabling confident decisions without the false-positive burden that plagues traditional tools.

Recent Articles By Author
  • Cogent: AI Exploit Developer Threats Outpace Scanner Detection On Critical Vulnerabilities
  • F5 Strengthens, Scales & Sustains AI Security With Integrated Runtime Protection 
  • Arcjet Python SDK Sinks Teeth Into Application-Layer Security 
More from Adrian Bridgwater
February 2, 2026January 30, 2026 Adrian Bridgwater Application Security, Cybersecurity, Data Security, Information Security, Malware, Security News
  • ← How to read DMARC reports: Enterprise guidance
  • Flaw in Broadcom Wi-Fi Chipsets Illuminates Importance of Wireless Dependability and Business Continuity  →

Techstrong TV

Click full-screen to enable volume control
Watch latest episodes and shows

Tech Field Day Events

Upcoming Webinars

True Agentic SecOps at Lakehouse Scale
Agentic Software Delivery in 2026: How To Bridge The Gap Between AI Ambition and Delivery Confidence
Untangling the EU Cyber Resilience Act
The Software Supply Chain Just Got Harder to See
Building a Resilient Security Culture in the AI Era with AWS & Datadog

Podcast

Listen to all of our podcasts

Secure by Design

3 weeks ago | Jack Poller

Senator Sanders Wants to Own AI Companies — and Hand America’s Adversaries the Keys

4 weeks ago | Jack Poller

NIST’s Nine: The PQC Signature Race Moves to Round Three

4 weeks ago | Jack Poller

The Quantum Arms Race: Why Washington Just Wrote a $2 Billion Check to Nine Companies

1 month ago | Jack Poller

Beyond Moore’s Law: The Hyper-Acceleration of Autonomous AI Cyber Capabilities

1 month ago | Jack Poller

The Exception Economy: When Security Teams Stop Protecting and Start Negotiating

Press Releases

GoPlus's Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

Subscribe to our Newsletters

Most Read on the Boulevard

MSG Breach: Knicks Take the NBA Championship, ShinyHunters Takes the Data 
F5 Embeds Neural Network in WAF Platform to Continuously Assess Risks
France to Stop Certifying Products Without Quantum-Safe Encryption in 2027
Trying to Control AI is Like Holding Sand
Barracuda Networks Enlists AI to Protect Email Systems
FortiBleed Leak Exposes VPN Credentials for Nearly 74,000 Fortinet Devices
GitHub Locks Down npm: What the New Install Defaults Mean for Your Supply Chain
973 MCP Packages, 71% Single-Maintainer: A Practitioner’s Guide to AI Developer Security
Novo Nordisk Reports Cybersecurity Breach Affecting Clinical Trial Patients
Physical AI Agents: The Future of Autonomous Operations and Real-Time Enterprise Decision-Making in 2026

Industry Spotlight

NYC Sewers Crawling With Rats and Potential Bad Actors 
Cybersecurity Featured Industry Spotlight Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches 

NYC Sewers Crawling With Rats and Potential Bad Actors 

June 18, 2026 Teri Robinson | 4 days ago 0
Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
Cloud Security Cybersecurity Data Privacy Data Security Featured Incident Response Industry Spotlight Malware Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches Vulnerabilities 

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks

April 12, 2026 Jeffrey Burt | Apr 12 Comments Off on Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
The Day the Security Music Died
AI and Machine Learning in Security Cybersecurity Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

The Day the Security Music Died

April 8, 2026 Alan Shimel | Apr 08 Comments Off on The Day the Security Music Died

Top Stories

Job Seekers Make for Vulnerable Targets
Cybersecurity Data Privacy Data Security Featured News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

Job Seekers Make for Vulnerable Targets

June 19, 2026 Teri Robinson | 3 days ago 0
MSG Breach: Knicks Take the NBA Championship, ShinyHunters Takes the Data 
Cybersecurity Data Security Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

MSG Breach: Knicks Take the NBA Championship, ShinyHunters Takes the Data 

June 18, 2026 Teri Robinson | 3 days ago 0
Trying to Control AI is Like Holding Sand
AI and Machine Learning in Security Cybersecurity Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

Trying to Control AI is Like Holding Sand

June 17, 2026 Alan Shimel | 4 days ago 0

Security Humor

Fortinet® Follies

Fortinet® Follies

Download Free eBook

[su_panel border="0px solid #ddd" radius="0" text_align="center" padding-top="0px" padding-bottom="0px"]
7 Must-Read eBooks for Security Professionals
[/su_panel]

Security Boulevard Logo White

DMCA

Join the Community

  • Add your blog to Security Creators Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: [email protected]

Useful Links

  • About
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • DMCA Compliance Statement
  • Privacy Policy

Related Sites

  • Techstrong Group
  • Cloud Native Now
  • DevOps.com
  • Digital CxO
  • Techstrong Research
  • Techstrong TV
  • Techstrong.tv Podcast
  • DevOps Chat
  • DevOps Dozen
  • DevOps TV
Powered by Techstrong Group
Copyright © 2026 Techstrong Group Inc. All rights reserved.
×

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.