MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
Cybercriminals recruiting voice-phishing callers on Telegram contradicted themselves by claiming no script-reading while providing the exact script. This demonstrates poor operational security in social-engineering attacks targeting Google users.
Salesforce Agentforce contained three critical vulnerabilities allowing attackers to hijack AI agents, steal CRM data without user interaction, and send phishing messages. Zenity Labs discovered the flaws and Salesforce has patched them, but the incident highlights risks in AI-driven business applications.
UK authorities arrested 2 suspects linked to EvilTokens, a Microsoft device-code phishing kit. Microsoft-led coalition seized 50+ phishing websites and notified victims. The kit compromised 12,000 email inboxes across 10,000+ organizations since February.
Cisco Secure Email Gateway contains a critical flaw (CVE-2026-76461) allowing attackers to gain root access via malicious email. The 9.8 CVSS vulnerability affects all appliances with no workarounds, requiring immediate patching. Email security professionals must prioritize updates to prevent full system compromise.
BigBear phishing crew harvested thousands of Microsoft 365 credentials and session cookies across hundreds of organizations. The operation, using Evilginx2-based phishing-as-a-service, captured hundreds of authenticated sessions capable of bypassing MFA. Researchers gained access to the attackers' admin panel, revealing unprecedented campaign details.
Microsoft detected a massive phishing campaign using invisible Unicode characters (ASCII smuggling) to bypass email security filters, peaking at 2.37 million messages. Threat actors adapted AI-era techniques for traditional email phishing attacks. This highlights how obfuscation methods evolve to evade email defenses.
Law enforcement and CrowdStrike disrupted the 23-year-old Sality peer-to-peer botnet affecting 15,000+ machines worldwide. The botnet distributed malware enabling credential theft, spam, proxying, and DDoS attacks. This takedown protects organizations from ongoing malware delivery and credential compromise risks.
Russian cyber-spy groups are conducting targeted phishing campaigns against European and US academics, aerospace, defense, and government officials, abusing OAuth to enhance their attacks. Google has identified three distinct groups running ongoing operations with fewer than 100 targets each.
An attacker phished a US defense supplier's employee to compromise their Microsoft 365 account. The attacker posed as a business contact and sent a fake Microsoft sharing link, gaining access to the organization's email environment and sensitive data.
Russian espionage group TA488 expanded its half-click phishing attacks from Zimbra to Microsoft Outlook Web Access, exploiting CVE-2026-42897 (XSS flaw in Exchange Server OWA). The attack requires minimal user interaction, posing significant risk to enterprise email environments.
Russian state-sponsored attackers have exploited a Zimbra vulnerability for over a year, infecting targets automatically when viewing emails—without requiring clicks or file downloads. The campaign, attributed to Laundry Bear, affected government and commercial networks across the US, UK, and allies since July 2025.
German law enforcement shut down Kratos, a widespread phishing-as-a-service kit, with support from US and Indonesian authorities. The operation targeted the infrastructure supporting one of the market's most dangerous PhaaS platforms and resulted in arrests. This disruption significantly impacts threat actors relying on Kratos for phishing campaigns.
Attackers are using text salting to evade AI-powered email filters by hiding benign words in phishing emails. Barracuda detected over one million retail-themed phishing attacks using this technique since April, showing that traditional obfuscation methods remain effective against modern defenses.
Cybercriminals impersonate IT support via Microsoft Teams to trick employees into installing EtherRAT malware. Attacks begin with phishing emails posing as employee surveys, followed by Teams calls requesting remote access. This targets organizations broadly through a multi-stage social engineering campaign.
EvilTokens device-code phishing kit bypasses MFA and authenticates to Microsoft 365 as victims. Cisco Talos revealed new evasion techniques and capabilities, highlighting the threat's sophistication to email security professionals managing organizational defense.