Latest News

Rustam Kolchin: “A site that only shows its fraud to the right visitor learned to lie to security tools.”

Rustam Kolchin

Head of Cybersecurity Product Development at Softline and creator of Mail Security Guardian, the platform behind a 93% drop in phishing across 3 million real messages — on how to catch what a scanner can no longer see and contain what still gets through. 

In May 2026, the Anti-Phishing Working Group’s Q1 report found phishing attacks up 14% quarter over quarter, to almost 1,000,000 sites. A growing share of them now show nothing suspicious unless the visitor arrives through the exact search term or social post the attacker is targeting. Everyone else (including a security scanner) sees a blank or harmless page. Scanning a site and judging whether it looks malicious doesn’t work anymore, because the site can tell who’s looking. 

We talked to Rustam Kolchin, a professional with close to twenty years in cybersecurity who has built Mail Security Guardian, a platform that catches phishing and malware before they ever reach an inbox, and a Zero Trust system that governs human and machine access under one continuous-verification model. His work now protects enterprises across CIS. He’s a judge for the Velto European Awards, made the 2026 TOP-40 Digital Experts list, and has four peer-reviewed papers laying out exactly how those systems work. 

We spoke with him about how enterprises can detect attacks that scanners no longer catch, contain the credentials that inevitably slip through, and make identity the real control point. 

Rustam, as an expert who has been building cybersecurity systems for almost twenty years, does a finding like phishing sites hiding fraudulent content from scanners and only showing it to the intended victim feel like a new kind of threat to you?

The same threat, much better dressed. Phishing has always relied on the trick: get someone to trust something that isn’t what it claims to be, and that hasn’t changed in twenty years. What’s changed is that the trust used to break down somewhere obvious: bad grammar, a mismatched logo, a link that clearly didn’t match the sender, and a scanner could catch a lot of it just by looking. A site that only shows its fraudulent page to a visitor arriving from a specific search term or a specific social post has effectively learned to lie to the people checking its homework. Once a site can tell the difference between a security tool and a real target, you’re looking at a problem that has to be solved somewhere else entirely, because the old checkpoints don’t exist anymore.

Your ‘Application of Artificial Intelligence in Digital Risk Protection and External Threat Intelligence,’ in the International Journal of Modern Computer Science and IT Innovations, is about catching fake infrastructure. If AI-generated content is now nearly impossible to distinguish from the real thing, what’s left to detect? 

The infrastructure behind the content, which is much harder to fake convincingly than the content itself. 

A cloned login page can be flawless now, but registering a domain, provisioning a certificate, standing up hosting, these leave a trace long before the fake site gets meaningful traffic. The paper works through how AI can be pointed at exactly that layer instead of the layer that’s already lost: homoglyph detection to catch look-alike domains, dark web monitoring for leaked credentials before they’re used, and ranking which signals actually deserve a takedown request rather than burying a security team in noise. It’s a real shift in where the fight happens. For years, detection meant reading the message and judging whether it sounded legitimate. That’s over. What still works is watching the scaffolding an attacker has no choice but to build, because you can’t run a convincing fake site on no infrastructure at all, no matter how good the AI writing it is.

Your paper on Mail Security Guardian, in the International Journal of Advanced Artificial Intelligence Research, reports impeccable precision and a phishing reduction of 93%, based on a real six-month deployment across over 3 million messages. If a system built around the inbox is producing results like that, why does email remain the front line when so much else has changed? 

Because the target hasn’t moved, even though everything around it has. Email is still the fastest way to reach one specific person directly, and that’s exactly why attackers keep coming back to it no matter how sophisticated the rest of their infrastructure gets. What actually changed is how early you have to catch something. 

MSG routes everything through pre-SMTP reputation filtering, protocol authentication with SPF, DKIM, and DMARC, machine-learning content analysis, sandbox detonation for attachments and links, and a decision engine, all before a message reaches a human inbox, because by the time an AI-polished email lands in front of someone, you’ve already lost the easiest opportunity to stop it. Those numbers didn’t come out of a clean detection trick, they came from moving the entire fight earlier, before a person has to make a judgment call about whether an email looks right. The results prove that pre-delivery is the only model left that still works once the content itself has stopped being a reliable signal. 

Even a system as good as MSG isn’t going to catch everything, some phishing is still going to get through and hand over a credential. Your ‘Architectural Principles of Zero Trust Privileged Access Management in Modern Corporate Infrastructures,’ in the International Journal of Computer Science & Information System, argues that once that happens, identity is the only thing left to check. Why does the fight move there? 

Because once a phishing site is good enough to fool the scanner, you have to assume some percentage of those credentials are going to get through, and at that point the fight isn’t at the door anymore, it’s wherever that stolen credential tries to do something. That’s the layer Zero Trust actually interrogates. Instead of “does this traffic look suspicious,” it is “should this identity, on this device, be allowed to make this specific request at all,” regardless of whether it walked in through a legitimate login or a stolen one. The paper goes further than the usual version of that idea, because most Zero Trust literature still treats identity as a person typing a password. In a real enterprise, a huge share of privileged access belongs to something that isn’t a person, a deployment pipeline, an automation script, a service account nobody remembers provisioning. Those don’t fit the old access models, and they’re exactly the kind of identity an AI-driven attack is now fast enough to compromise and abuse before a human would even notice. 

The model in the paper governs both under one continuous-verification standard, short-lived sessions instead of standing trust, and one audit trail regardless of whether the requester is a person or a script. If you can’t stop every credential from being stolen at the front door, identity verification on the inside is what’s left, and it has to cover machines as seriously as it covers people. 

In “Transition from Periodic Security Assessments to Continuous Vulnerability Management Frameworks,” you suggest a new approach to vulnerability management. What does the combined model catch that separate teams miss? 

The gap you catch opens up between the functions, not inside any single one of them. Attack surface management on its own tells you a new asset showed up. Vulnerability intelligence on its own tells you a new exploit started circulating. Keep those as two separate teams reporting on two separate dashboards, and nobody necessarily connects a newly exposed asset to a working exploit for exactly what’s running on it, sometimes for weeks.

The model ties discovery, exploitation-aware prioritization, and remediation into one pipeline specifically so that connection gets made the moment it’s true. If a new exploit lands and it matches something already sitting on the external footprint, that jumps to the top of the queue automatically, instead of waiting for the next scheduled review.

And remediation verification is the part programs skip most, because an automated scan reporting a fix isn’t the same as a person confirming the fix actually closed the door. That’s usually where an old vulnerability quietly comes back, and it’s the piece the other three functions don’t catch on their own.

The Digital Leaders award named you ‘Developer of the Year’ for your continuous testing system, built on exploitation-aware prioritization instead of a static severity score. How do you decide what’s exploitable right now versus what’s just theoretically risky?

A static severity score tells you how bad a vulnerability could be in the abstract, not whether anyone can actually reach it from where they’re standing. What the system does instead is treat every finding as a question with context attached: is this asset actually exposed to the internet right now, is there a known, working exploit for it in the wild, and is it sitting next to something valuable enough to be worth an attacker’s time? 

A critical vulnerability on a forgotten test server nobody can route to is a lower priority than a moderate one sitting in front of a payment system, and a static score can’t tell you that, it just sees “critical” and “moderate.” The engine correlates fresh threat intelligence against the live asset inventory continuously, so a finding that was low priority on Monday can jump to the top of the list on Wednesday because a proof-of-concept exploit got published, without anyone having to re-run a scan. That’s the part that actually changes what a security team does with their time, they stop working through a severity-sorted list and start working through a list sorted by what’s genuinely reachable and dangerous today. 

You’re now judging for the Velto European Awards yourself on a similar kind of professional jury panel that gave you that Digital Leaders award. How many of the companies you review are really building around continuous verification and identity as the control point?

Genuinely a mix, maybe a third of what I see is actually built that way, and the rest is still fighting the old fight with newer language. The strong ones describe an architecture that assumes the perimeter is gone, continuous verification, identity as the control point, monitoring that doesn’t stop at 5 pm. The weak ones still describe a better filter, a smarter way to catch the bad email or the bad file, as if the fight is still happening at the point of detection. That’s not a dishonest pitch, usually, it’s just outdated thinking dressed up in AI language, because “AI-powered detection” sounds current even when the underlying model is the same reactive checkpoint that stopped being sufficient once sites and lures learned to hide from the tools checking them. Reading that pattern over and over has made me more convinced that the shift toward identity and continuous verification isn’t a trend, it’s the actual floor now, and companies that haven’t rebuilt around it are going to find that out the hard way.

At CSX North America, the flagship conference of ISACA, the global association for security professionals, you presented your unique AI-based approaches to detecting botnet activity and took live questions from teams that monitor a company’s systems. What does a working security team need from all of this that a report never captures? 

To my mind, they need to know where it’s going to break in their own environment. That came through in the questions after the talk. People weren’t asking about the concept, they wanted to know where the false positives would show up on their setup, how much tuning it would actually take, whether “continuous monitoring” just meant more noise for a three-person team to drown in. And that’s really the gap. A stat like phishing up 14% in a quarter is one thing. A SOC trying to get through an ordinary day is a completely different thing. You can publish all the research you want about identity being the new perimeter, but somebody still has to make least-privilege access work without breaking the deployment pipeline, and somebody still has to roll out continuous monitoring without burying three analysts in alerts. That’s where it actually gets decided. Not in a report. In whether a real team can keep running the thing, day after day, without burning out. 

After years watching credential theft and identity-based attacks up close, has it changed anything about how you personally manage your own passwords or accounts? 

It has. I used to be like most people, one password I felt okay about, reused in a few places I shouldn’t have. Now I use a password manager for everything and a hardware key wherever I can. Honestly, designing systems that assume no credential can be trusted made it hard to keep trusting my own. 

Comments

TechBullion

FinTech News and Information

Copyright © 2026 TechBullion. All Rights Reserved.

To Top

Pin It on Pinterest

Share This