MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
This week in email security
AI briefing · 2026-08-23
Phishing tactics evolve beyond passwords: passkeys, MFA bypass, and AI agents dominate threats
iAuthFlow V2 and Mirage2FA represent a shift in attacker persistence: malware now maintains access by registering passkeys or stealing authenticated sessions after MFA completion, rendering traditional post-breach password resets ineffective.
Russian and Chinese-nexus APT groups are escalating targeted campaigns against government, defense, and aerospace sectors using OAuth abuse and spear-phishing with RATs, signaling state-sponsored operational tempo.
Attackers are combining obfuscation techniques—Unicode emojis, fake software installers, AI voice—with social engineering at scale, exploiting routine user behaviors like software downloads and conference attendance rather than advanced exploits.
Criminal AI services and phishing-as-a-service platforms are democratizing sophisticated attacks: MessiahGPT and similar tools lower barriers for mass campaigns while AI-driven intent-based phishing outpaces signature and payload detection.
Traditional email security defenses face a fundamental challenge as threat actors pivot toward AI agents, authenticated session theft, and multi-factor attack chains where blocking malware alone no longer stops compromise.
A large-scale phishing campaign used SVG attachments disguised as voicemail notifications to evade email security controls. The attack targeted 5527 organizations with 26,000+ malicious messages, exploiting attachment-based delivery to breach email defenses.
A security researcher documents a polymorphic phishing page that dynamically changes appearance to evade detection. The attacker's code occasionally malfunctions, causing the phishing page to break. This demonstrates obfuscation techniques used in active phishing campaigns.
NovaCookies, a $320/month AitM phishing toolkit, abuses legitimate DocuSign notifications to redirect Microsoft 365 logins and steal authenticated sessions. The subscription-based platform poses significant risk to organizations by compromising M365 credentials through email-based social engineering attacks.
NovaCookies is a phishing-as-a-service kit enabling attackers to conduct adversary-in-the-middle attacks against Microsoft 365 users, stealing session cookies beyond credentials for $320/month. This lowers the attack complexity for email-based credential harvesting campaigns targeting enterprise cloud environments.
Criminals are using AI voice agents to impersonate Apple Support, targeting stolen-device owners to extract passcodes and 2FA codes via phishing calls. The AnonyMousKIT platform enables bypassing Apple's Activation Lock on stolen devices through a phishing-as-a-service model.
ZeroTokens is a phishing platform enabling attackers to control victim sessions in real time, targeting 53 financial institutions. The tool allows dynamic attack steering, posing a significant threat to enterprise email security and authentication systems.
WhatsApp now supports multiple passkeys per account on iOS and Android, enabling phishing-resistant sign-ins. Over 1 billion users already rely on passkeys. This enhancement strengthens account security against credential-based attacks.
RecruitTrap campaigns are using mobile-optimized phishing pages to impersonate recruiters and steal corporate credentials. The scam targets enterprise employees through mobile devices, attempting to harvest login credentials at scale.
Mirage2FA, a phishing-as-a-service toolkit, compromised 4,500+ US and EU companies by abusing Microsoft 365 login flows to bypass 2FA. The campaign affected 48% of targeted email addresses. This directly impacts email security professionals defending against credential theft and account takeover attacks.
ReliaQuest confirmed that ShinyHunters hackers exploited a phishing-compromised employee account to access a dashboard, though the company states the impact was limited. This incident demonstrates the persistent threat of phishing targeting enterprise security firms.
Researchers discovered iAuthFlow V2, a phishing toolkit that registers attacker-controlled passkeys to maintain persistent access even after victims reset passwords or revoke active sessions. This represents a novel persistence mechanism that bypasses traditional account recovery measures.
Cybercriminals disguise malware as a Google Gemini installer to distribute Vidar stealer, targeting saved browser passwords and credentials. The attack exploits routine software searches rather than email phishing, demonstrating credential-theft risks from trojanized downloads.
Russian cyber-spy groups are conducting targeted phishing campaigns against European and US academics, aerospace, defense, and government officials, abusing OAuth to enhance their attacks. Google has identified three distinct groups running ongoing operations with fewer than 100 targets each.