MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
A phishing campaign using Canadian tax forms has expanded to 46 countries, with 45% of attacks targeting the US. The campaign delivers Remote Monitoring and Management (RMM) malware via deceptive tax documents, representing a significant threat to organizations globally.
NovaCookies, a $320/month AitM phishing toolkit, abuses legitimate DocuSign notifications to redirect Microsoft 365 logins and steal authenticated sessions. The subscription-based platform poses significant risk to organizations by compromising M365 credentials through email-based social engineering attacks.
Criminals are using AI voice agents to impersonate Apple Support, targeting stolen-device owners to extract passcodes and 2FA codes via phishing calls. The AnonyMousKIT platform enables bypassing Apple's Activation Lock on stolen devices through a phishing-as-a-service model.
WhatsApp now supports multiple passkeys per account on iOS and Android, enabling phishing-resistant sign-ins. Over 1 billion users already rely on passkeys. This enhancement strengthens account security against credential-based attacks.
Mirage2FA, a phishing-as-a-service toolkit, compromised 4,500+ US and EU companies by abusing Microsoft 365 login flows to bypass 2FA. The campaign affected 48% of targeted email addresses. This directly impacts email security professionals defending against credential theft and account takeover attacks.
Phishing tactics have evolved beyond payload-based detection toward AI-driven attacks where intent matters more than content. Traditional email defenses struggle as attackers increasingly use AI agents, requiring defenders to adopt new strategies.
CTM360 discovered over 3,000 recruitment phishing URLs using Browser-in-the-Browser technique to steal Google and Facebook credentials and intercept MFA prompts. The global campaign targets job seekers with fake interview pages. This represents a significant phishing threat exploiting social engineering and advanced credential-theft tactics.
North Korean Kimsuky group deployed offline AI systems to enhance phishing campaigns and automate malware development, reducing reliance on public chatbots and leveraging stolen documents for espionage operations.
Researchers discovered three attack methods bypassing passkey protections: exploiting Windows authentication material exposure, abusing cloud-synced passkeys via malware, and using phishing-resistant MFA workarounds. Passkeys are increasingly used for email account protection, making these attacks directly relevant to email security practitioners.
UNC6671, a data extortion group, conducts vishing attacks on personal phones impersonating IT staff to trick enterprise employees into compromising SaaS credentials. The campaign targets financial services, private equity, and professional services sectors, bypassing traditional email security controls.
Researchers discovered an active phishing campaign using adversary-in-the-middle techniques to compromise Microsoft 365 accounts and extract payroll and finance emails. Attackers use residential proxies to mask malicious sign-ins, targeting financial personnel.
Kali365 phishing kit exploits Microsoft authentication to target US companies. Attackers trick users into approving device codes on legitimate Microsoft pages, stealing access tokens to compromise email, documents, and cloud resources.
Greatness PhaaS now supports device code phishing to bypass MFA and steal OAuth tokens. This technique abuses legitimate OAuth 2.0 Device Authorization Grant flows. Critical threat for organizations as attackers can compromise accounts despite MFA protections.
HollowFrame loader and Matryoshka backdoor were deployed via spear-phishing targeting a law firm. The attack chain began with a phishing email containing a link to an encrypted archive with a malicious LNK file. This undocumented Go and Rust malware represents a sophisticated multi-stage threat.