MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
This week in email security
AI briefing · 2026-09-27
AI-powered phishing escalates while Microsoft dismantles EvilTokens infrastructure
Microsoft disrupted EvilTokens, an AI-powered phishing-as-a-service platform that compromised over 12,000 inboxes across 10,000 organizations, with UK law enforcement arresting suspects and seizing 50+ websites.
Salesforce Agentforce vulnerabilities enabled zero-click data theft and phishing injection into Slack, demonstrating how AI agents can be weaponized to bypass traditional security controls and abuse trusted communication channels.
Attackers are increasingly poisoning AI systems and manipulating chatbots to seed malicious links and data, which then propagate through ChatGPT, Gemini, and Google AI responses for mass disinformation and phishing campaigns.
Threat actors use multi-layered evasion techniques including DLL side-loading, in-memory decryption, URL obfuscation, and malicious script distribution via social engineering, targeting both enterprise users and specific verticals like financial services.
Email phishing analysis consumes nearly one-third of MSSP Tier 1 workload, underscoring the operational burden defenders face as attacker sophistication and campaign volume continue to rise.
Phishing campaigns impersonate meeting invitations and software updates to trick users into installing MSP360 RMM software, which attackers then abuse to deploy ScreenConnect for dual-RMM control. This gives threat actors persistent remote access to compromised systems, affecting organizations relying on RMM tools.
Article describes a 3-step approach for SOC teams to investigate phishing alerts more efficiently, addressing challenges like encrypted traffic and obfuscation techniques that slow analysis and response.
Global Group cybercriminals use payment-themed phishing emails delivering malicious ISO files and legitimate WinMerge tool to deploy ransomware against enterprises. Attackers establish persistence before encryption to facilitate extortion. This phishing-to-ransomware chain targets email security defenses.
Russia's Star Blizzard APT group has abandoned ClickFix attacks for a new "RedFlick" phishing tactic targeting Ukrainian organizations. The campaign delivers the CosmicPulse backdoor to NGOs, think tanks, and journalists, representing an evolution in their phishing delivery methods and a direct threat to email security defenses.
Star Blizzard, a Russian FSB-linked group, has escalated phishing attacks against Ukraine supporters using new infection techniques. The group is expanding operations with improved malware delivery methods, posing heightened risk to targets supporting Ukraine.
A phishing campaign impersonates Amazon Prime with fake billing alerts to steal customer logins, personal data, and payment card details. This directly targets email users through credential harvesting and financial fraud schemes.
Russian APT Star Blizzard conducts phishing campaigns using the RedFlick infection chain to deploy the CosmicPulse backdoor. This represents a broader attack capability for the state-sponsored group targeting enterprise environments.
A US-focused phishing campaign targets C-suite executives, stealing Microsoft 365 sessions and deploying remote-access tools (RMM) for persistent compromise. Technology, manufacturing, government, and consulting sectors are heavily affected. This escalates phishing from credential theft to enterprise-wide account takeover.
RATHat Android malware leverages Gemini AI to control infected phones while evading normal permission restrictions. Distributed via malicious ads and phishing SMS, it exploits Accessibility features to establish persistent command channels targeting users in Europe, Latin America, and Southeast Asia.
Article discusses how US SOCs and MSSPs can leverage threat intelligence to detect phishing infrastructure earlier by understanding the complex network of domains, compromised sites, redirectors, and cloud services attackers use behind phishing links.
Phishing exposure has reached nearly 70% across major US industries, with finance and manufacturing most affected. Security teams must enhance detection, awareness training, and email filtering to defend critical sectors.
Cofense Vision now integrates with Google Workspace to detect and remove phishing threats that bypass perimeter defenses and reach Gmail inboxes. The solution helps security teams identify and remediate sophisticated phishing attacks post-delivery. This addresses the gap where advanced threats evade traditional email security controls.
Cybercriminals recruiting voice-phishing callers on Telegram contradicted themselves by claiming no script-reading while providing the exact script. This demonstrates poor operational security in social-engineering attacks targeting Google users.