
TRC analysis shows attackers are weaponizing open redirects in CVE-2026-1277 and CVE-2026-2153 to bypass email security filters. Phishing campaigns leveraged trusted domains like Google Meet to steal credentials, then moved laterally through cloud environments. Runtime segmentation helps contain post-compromise lateral movement. #Phishing #ZeroTrust :link: Full TRC analysis: https://aviatrix.ai/threat-research-center/phishing-campaigns-exploit-open-redirects-2026
Post summary
The analysis reports that CVE‑2026‑1277 and CVE‑2026‑2153 are actively exploited by attackers through open‑redirect payloads in phishing campaigns to bypass email security filters, illustrating real‑world exploitation in cloud environments.
