MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
Cruciferra, a sophisticated crypter service, hides Windows malware using BYOVD and process ghosting techniques. The China-linked group uses it for tax-related phishing campaigns targeting Indian taxpayers and finance teams. The tool enables malware delivery while evading detection.
Insurance phishing attacks have evolved from credential harvesting to real-time account hijacking, with attackers immediately compromising accounts during phishing sessions rather than storing credentials for later use. This represents a significant shift in attack tactics targeting financial institutions and insurance firms.
North Korean threat actor BlueNoroff operates a phishing kit impersonating Zoom and Microsoft Teams to deliver malware. The campaign profiles cryptocurrency wallets before malware delivery, exploiting typosquatted domains to compromise targets through social engineering.
AegisAI secured $36 million in Series B funding, bringing total investment to $49 million. The company develops AI-powered email security solutions. Relevant to email-security professionals tracking emerging vendors and technology advancements.
A critical vulnerability in ChatGPT Workspace Agents (AgentForger) could allow attackers to deploy rogue AI agents via phishing links. The flaw enabled building and authorizing autonomous agents within victim organizations. OpenAI patched the issue as of June 8.
ChatGPT entered the top 10 most impersonated brands in phishing attacks according to Check Point research. Attackers are leveraging the brand's popularity to deceive users. This represents a growing threat vector email security professionals must monitor and defend against.
Russian hackers exploit a Zimbra zero-day vulnerability, sending "half-click" phishing emails requiring only message preview to compromise US and Ukraine targets. The state-sponsored group Laundry Bear leverages this technique for low-friction exploitation.
Russia-linked group Laundry Bear is exploiting Zimbra webmail with zero-click phishing attacks affecting users globally. U.S. and international partners issued an alert about the campaign targeting webmail accounts.
Russian state-sponsored attackers have exploited a Zimbra vulnerability for over a year, infecting targets automatically when viewing emails—without requiring clicks or file downloads. The campaign, attributed to Laundry Bear, affected government and commercial networks across the US, UK, and allies since July 2025.
Cofense webinar highlights how AI is enabling more sophisticated, scalable phishing campaigns. Security teams must evolve detection strategies beyond individual emails to combat adaptive threat tactics.
German and US law enforcement dismantled Kratos, a major phishing kit designed to steal Microsoft 365 sessions and bypass MFA. An Indonesian developer was arrested. This takedown disrupts a widely-used criminal tool targeting email accounts globally.
PhantomEnigma campaign hijacks 20+ Brazilian government websites to distribute malware via trusted domains. Attackers compromised government mailboxes to send authenticated phishing emails bypassing SPF/DKIM/DMARC checks, targeting banking and public-sector organizations.
German law enforcement shut down Kratos, a widespread phishing-as-a-service kit, with support from US and Indonesian authorities. The operation targeted the infrastructure supporting one of the market's most dangerous PhaaS platforms and resulted in arrests. This disruption significantly impacts threat actors relying on Kratos for phishing campaigns.
APT42, an Iran-linked APT, is conducting sophisticated phishing campaigns against government and defense officials using AI-assisted research and realistic social engineering tactics, coupled with an updated TAMECAT malware variant designed for persistence and evasion.
A misconfigured WebDAV server exposed a malware factory containing over 1,000 attack files, including phishing lures, droppers, and malware variants. The GenAI-powered operation targeted Windows users with fake documents and malicious shortcuts. The discovery reveals detailed insights into attacker infrastructure and malware development practices.