MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
Global Group cybercriminals use payment-themed phishing emails delivering malicious ISO files and legitimate WinMerge tool to deploy ransomware against enterprises. Attackers establish persistence before encryption to facilitate extortion. This phishing-to-ransomware chain targets email security defenses.
A phishing campaign impersonates Amazon Prime with fake billing alerts to steal customer logins, personal data, and payment card details. This directly targets email users through credential harvesting and financial fraud schemes.
Phishing exposure has reached nearly 70% across major US industries, with finance and manufacturing most affected. Security teams must enhance detection, awareness training, and email filtering to defend critical sectors.
Microsoft disrupted EvilTokens, an AI-powered phishing service that compromised 12,000 inboxes across 10,000 organizations and facilitated financial fraud. The threat targeted email accounts at scale using advanced techniques.
Revolut customers face phishing attacks via text messages following a data breach that exposed personal information like IDs and selfies. Attackers are leveraging exposed data to conduct targeted phishing campaigns against financial service users.
Phishing emails impersonating OpenAI billing notices are targeting ChatGPT users to steal credentials and payment details. Cofense researchers discovered the campaign. This directly threatens email users and demonstrates credential harvesting via email deception.
Security researchers discovered the GhostCode phishing kit that exploits Microsoft OAuth to bypass MFA protections and steal credentials for Microsoft 365 accounts. The kit uses token-stealing techniques to gain unauthorized access despite multi-factor authentication being enabled, posing a significant threat to enterprise email security.
Phishing emails impersonating sexual misconduct allegations target universities, delivering fake Google Drive links that install Zoho RAT malware. Healthcare-linked institutions are primary targets. This demonstrates email's continued role as the primary attack vector for malware distribution.
Researchers discovered a phishing service streaming real Google login pages to attackers in real-time, enabling interception of passwords, 2FA codes, and authenticated sessions. This sophisticated credential-theft technique poses significant risk to organizations relying on Google Workspace for email and collaboration.
Article explains how exposed email addresses facilitate phishing and account takeover attacks, detailing threat mechanisms and defensive practices. Directly addresses email-security risks and protection strategies relevant to security professionals managing email infrastructure and user security.
MessiahGPT, an unrestricted criminal AI service, offers malware, phishing, and fraud capabilities on BreachForums. The platform provides 50 free queries and paid subscriptions from $8, representing a significant threat as it democratizes attack tools for cybercriminals targeting organizations.
A crypto exchange reduced phishing rates by 8x using phishing simulations and behavioral defenses. The findings highlight social engineering as a critical threat vector in the crypto industry, offering actionable insights for security defense strategies.
Kali365 threat actor exploits Microsoft device login flows to obtain OAuth tokens for unauthorized corporate data access targeting US firms. SOC teams must enhance detection of phishing attacks leveraging this authentication bypass method.
Phishing emails with malicious TTF (TrueType Font) files attached are being used to deliver Windows malware. The attack disguises malware as legitimate business documents, exploiting users who trust font files. This represents a novel email-borne malware delivery technique targeting organizations.