Skip to content
Phishing Attackers Exploit Safe Links to Bypass Security Measures

Phishing Attackers Exploit Safe Links to Bypass Security Measures

First seen 17 Mar 2026, 11:38 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 18, 2026 at 11:27 UTC
  • •Phishing attackers are misusing URL rewriting to bypass security filters.
  • •This method targets enterprise email gateways, affecting many organizations.
  • •Cybersecurity professionals are advised to reassess their email security measures.

Threat actors are leveraging URL rewriting mechanisms in phishing campaigns to evade detection. This method abuses a security feature designed to protect users by replacing original links with URLs from security vendors that scan destinations in real-time. By weaponizing these trusted safe links, attackers can deliver malicious payloads that bypass detection filters. The attacks primarily target enterprise email gateways, affecting organizations that rely on these security measures. The scope of the impact is significant, as many enterprises utilize URL rewriting for email security. Current reports indicate that this tactic is becoming increasingly common, raising alarms among cybersecurity professionals. Organizations are urged to review their email security configurations to mitigate this risk.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 206d ago How this analysis works

Timeline

2026-03-17
Gbhackers and Cybersecuritynews report on URL rewriting abuse
Recent
Increased phishing attempts using safe links reported

More articles in this cluster (2)