MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
SideCopy, an India-focused threat actor, has expanded targeting to academic institutions via spear-phishing campaigns using ReverseRAT malware. The group leverages mshta.exe abuse to execute malicious scripts and bypass security controls, broadening from government to education sector targets.
A sophisticated ransomware group employs double-extortion tactics globally, infiltrating networks to encrypt data and threaten public disclosure of stolen information. The article examines ransomware attack methods and their impact on critical business systems across industries.
Revolut customers are experiencing a surge in phishing attacks following a recent data breach. Attackers are leveraging stolen customer data to craft convincing phishing messages. This represents a significant risk for email-based credential theft and fraud targeting financial services users.
Revolut customers face phishing attacks via text messages following a data breach that exposed personal information like IDs and selfies. Attackers are leveraging exposed data to conduct targeted phishing campaigns against financial service users.
Attackers are conducting a widespread SMS phishing campaign impersonating T-Mobile, claiming loyalty points are expiring to trick users into visiting malicious sites that steal login credentials, personal data, and payment information. The campaign began in May 2026 and persists through continuous variations.
RatHat is a China-based Android malware distributed via smishing and malvertising that uses AI for device control and persists through ADB abuse. It targets mobile devices with SMS phishing and fake app downloads, relevant to email security professionals monitoring phishing campaign vectors.
Phishing emails impersonating OpenAI billing notices are targeting ChatGPT users to steal credentials and payment details. Cofense researchers discovered the campaign. This directly threatens email users and demonstrates credential harvesting via email deception.
Security researchers discovered the GhostCode phishing kit that exploits Microsoft OAuth to bypass MFA protections and steal credentials for Microsoft 365 accounts. The kit uses token-stealing techniques to gain unauthorized access despite multi-factor authentication being enabled, posing a significant threat to enterprise email security.
BlackHatSect0r used a DeepSeek-powered AI agent to automate credential harvesting and phishing attacks, extracting 16,834 credentials through exposed security gaps. The exposed server revealed phishing tools and a custom DXSCAN platform, demonstrating how AI accelerates credential theft at scale.
RatHat Android malware steals banking PINs and credentials through fake screens, persists after deletion, and spreads via SMS phishing and malicious ads. It targets banking customers with account takeover and payment fraud risks.
Threat actors are leveraging ChatGPT's subscription model to conduct phishing attacks, sending fake payment update notifications to users. These familiar billing lures target ChatGPT's large user base to steal credentials and sensitive information.
A smishing campaign intercepts victims' card details and OTPs in real-time through fake payment pages impersonating official services. Attackers use shortened links and urgency tactics to trick users into entering sensitive information that criminals observe live.
PAPERMILL campaign uses phishing emails with fake tax-audit notices and Notepad++ signed binaries to deliver VenomRAT malware. Disk-image attachments bypass security email checks (SPF/DKIM/DMARC) and Windows warnings, targeting unsuspecting users with trojan deployment.
N0va phishkit targets US and EU businesses with sophisticated phishing campaigns impersonating trusted services to compromise legitimate accounts. Attackers bypass malware detection by leveraging valid credentials to access sensitive data and business systems, posing significant risk to organizations.
Cisco Secure Email Gateway contains a critical flaw (CVE-2026-76461) allowing attackers to gain root access via malicious email. The 9.8 CVSS vulnerability affects all appliances with no workarounds, requiring immediate patching. Email security professionals must prioritize updates to prevent full system compromise.