MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
Researchers demonstrated how Microsoft Copilot in Microsoft 365 can be weaponized for business email compromise (BEC) and wire fraud. A single compromised employee account can escalate to CEO takeover and steal $250,000 with minimal attacker effort, posing significant risk to email security.
Phishing remains the primary breach vector, now enhanced by generative AI and account-takeover (AiTM) techniques that bypass email gateways and MFA. Top SOCs are adopting real-time behavioral detonation and threat intelligence to counter dynamic browser-based attacks that traditional email security cannot stop.
Device code phishing attacks surged 1,500% in 2026, while vishing (voice phishing) doubled. These social engineering techniques bypass traditional security controls and minimize forensic traces.
Phishing campaigns are targeting AI solutions providers by impersonating AI services like ChatGPT. Attackers exploit users' fear of losing access or data to deliver phishing emails. This represents an emerging threat vector leveraging the popularity of AI platforms.
HollowFrame loader and Matryoshka backdoor were deployed via spear-phishing targeting a law firm. The attack chain began with a phishing email containing a link to an encrypted archive with a malicious LNK file. This undocumented Go and Rust malware represents a sophisticated multi-stage threat.
Device code phishing exploits OAuth 2.0 device authorization flows to steal access tokens at scale. Originally a red-team technique, it has become a widespread threat affecting various applications beyond input-constrained devices, posing significant risks to credential security and account access.
Adversary-in-the-Middle (AiTM) phishing has become the leading initial access vector for law firms, accounting for 56% of threats. This technique bypasses multi-factor authentication by intercepting credentials in real-time, posing severe risks to organizations handling sensitive client data.
Attackers used Teams-themed phishing to abuse Microsoft's legitimate login pages rather than hosting fake ones, making detection harder. Check Point researchers documented this campaign targeting users. This represents an evolution in phishing tactics that security professionals need to identify and defend against.
Russian espionage group TA488 expanded its half-click phishing attacks from Zimbra to Microsoft Outlook Web Access, exploiting CVE-2026-42897 (XSS flaw in Exchange Server OWA). The attack requires minimal user interaction, posing significant risk to enterprise email environments.
LogoKit phishing kit now generates victim-specific phishing pages using real-time screenshots of target websites, making phishing attacks more convincing and harder to detect. This advancement increases phishing campaign effectiveness against email recipients.
Cisco Talos analysis reveals phishing continues as the leading entry point for cyber-attacks, with hackers refining evasion techniques. This trend underscores the persistent threat of phishing against organizations and the need for robust email security defenses.
Researchers discovered a targeted phishing campaign using Telegram to compromise accounts of an exiled Belarusian activist and users in Russia and Kazakhstan. The highly personalized attack highlights credential theft risks through messaging platforms.
Operation BlueDash uses phishing emails falsely claiming document-sharing issues to trick users into installing a fake Microsoft Teams update, granting attackers dual remote-control capabilities. The campaign exploits email-based social engineering to deliver malware with multiple persistence mechanisms.
Operation BlueDash uses fake Microsoft Teams update lures to trick users into downloading legitimate RMM tools (Level and ScreenConnect), establishing remote access for potential credential harvesting or system compromise. This phishing campaign targets Teams users via compromised infrastructure and counterfeit Store pages.