Open redirect: secondstreetapp.com
Open redirect: Shibboleth SSO Logout Return Parameter
Open redirect: shoppermeet.net
Open redirect: shoppingwebapi.didatravel.com
Open redirect: Signature Travel Network
Open redirect: slubnaglowie.pl
Open redirect: smartadserver.com
Open redirect: social.bigpress.net
Open redirect: ssg-financial.com
Open redirect: stats.lib.pdx.edu
Open redirect: storematch.jp
Open redirect: Ticketmaster
Open redirect: tkqlhce.com
Open redirect: tuttocauzioni.it
Open redirect: unitedwaynwvt.org
Open redirect: U.S. Antarctic Program Data Center (USAP-DC)
Open redirect: vconfex.com
Open redirect: weblinkconnect.com
Open redirect: whitefox.pl
Open redirect: Xfinity CMP Redirection to Google AMP
Open redirect: xfinity.com
Open redirect: YouTube --> Google Redirection Chain
Outlook hyperlink bypass: left-to-right mark (LRM) in base HTML tag
PDF attachment with Google (AE) redirecting to a php or zip file
QR code to auto-download of a suspicious file type (unsolicited)
QR Code with suspicious indicators
Reconnaissance: Email address harvesting attempt
Recruitee Infrastructure Abuse
Request for Quote or Purchase (RFQ|RFP) with HTML smuggling attachment
Request for Quote or Purchase (RFQ|RFP) with suspicious sender or recipient pattern
Salesforce infrastructure abuse
Self-sent fake PDF attachment with misleading link
Service abuse: Apple TestFlight with suspicious developer reference
Service abuse: AppSheet infrastructure with suspicious indicators
Service abuse: Behance document sharing with suspicious language
Service abuse: Callback phishing via Microsoft Teams invite
Service abuse: File sharing impersonation with external SharePoint links
Service abuse: FlipHTML5 with attachment deception and credential theft language
Service abuse: Formester with suspicious link behavior
Service abuse: GitHub notification with excessive mentions and suspicious links
Service abuse: Google account notification with links to free file host
Service abuse: Google application integration redirecting to suspicious hosts
Service abuse: Google Firebase sender address with suspicious content