MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
Device code phishing exploits OAuth 2.0 device authorization flows to steal access tokens at scale. Originally a red-team technique, it has become a widespread threat affecting various applications beyond input-constrained devices, posing significant risks to credential security and account access.
Operation BlueDash uses fake Microsoft Teams update lures to trick users into downloading legitimate RMM tools (Level and ScreenConnect), establishing remote access for potential credential harvesting or system compromise. This phishing campaign targets Teams users via compromised infrastructure and counterfeit Store pages.
Cruciferra, a sophisticated crypter service, hides Windows malware using BYOVD and process ghosting techniques. The China-linked group uses it for tax-related phishing campaigns targeting Indian taxpayers and finance teams. The tool enables malware delivery while evading detection.
Insurance phishing attacks have evolved from credential harvesting to real-time account hijacking, with attackers immediately compromising accounts during phishing sessions rather than storing credentials for later use. This represents a significant shift in attack tactics targeting financial institutions and insurance firms.
North Korean threat actor BlueNoroff operates a phishing kit impersonating Zoom and Microsoft Teams to deliver malware. The campaign profiles cryptocurrency wallets before malware delivery, exploiting typosquatted domains to compromise targets through social engineering.
A critical vulnerability in ChatGPT Workspace Agents (AgentForger) could allow attackers to deploy rogue AI agents via phishing links. The flaw enabled building and authorizing autonomous agents within victim organizations. OpenAI patched the issue as of June 8.
German and US law enforcement dismantled Kratos, a major phishing kit designed to steal Microsoft 365 sessions and bypass MFA. An Indonesian developer was arrested. This takedown disrupts a widely-used criminal tool targeting email accounts globally.
Researchers at Rapid7 discovered an exposed server containing an AI-assisted phishing toolkit used in active malware campaigns. The toolkit, which includes lure templates and malware builders, was being deployed against Windows users in Mexico via WebDAV to deliver infostealers through spoofed government websites.
OkoBot malware framework targets hardware wallet users by injecting phishing prompts into legitimate Ledger and Trezor desktop applications to steal recovery phrases. Active since April 2025, the malware exploits trust in wallet software to compromise cryptocurrency assets on infected Windows systems.
Forg365, a phishing-as-a-service platform sold on Telegram for $400/month, targets Microsoft 365 accounts using device code phishing, AitM session theft, and AI-generated lures, followed by mailbox compromise. This threatens organizations relying on Microsoft 365 email and poses significant risk to email security defenders.
A misconfigured public web server exposed an active Evilginx phishing operation targeting Microsoft 365, revealing the attacker's toolkit and leading to discovery of two additional related operations. This demonstrates how poor operational security compromises sophisticated phishing infrastructure.
Attackers are using fake Microsoft Entra passkey enrollment prompts via voice-based phishing to compromise Microsoft 365 accounts across multiple sectors. The threat actor O-UNC-066 deploys a panel-controlled phishing kit targeting passkey enrollment, leading to data extortion attacks.
A new 'ghost phishing' technique in the EvilTokens campaign hides malicious pages until decryption in the victim's browser, bypassing traditional email security URL checks. Targets US and Europe businesses seeking Microsoft 365 access and sensitive data.
DEBULL tooling abuses Microsoft's legitimate device-code flow in a phishing campaign targeting M365 accounts using collaboration-themed lures, exploiting the device login process to compromise victim credentials without fake login pages.
Chinese-linked hackers targeted Indian taxpayers using spear-phishing emails impersonating the Income Tax Department to deliver DcRAT malware. The multi-stage campaign, named Operation DragonReturn, aimed to steal sensitive data from victims' systems via a fake tax filing utility.