MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
North Korean threat actor BlueNoroff operates a phishing kit impersonating Zoom and Microsoft Teams to deliver malware. The campaign profiles cryptocurrency wallets before malware delivery, exploiting typosquatted domains to compromise targets through social engineering.
A critical vulnerability in ChatGPT Workspace Agents (AgentForger) could allow attackers to deploy rogue AI agents via phishing links. The flaw enabled building and authorizing autonomous agents within victim organizations. OpenAI patched the issue as of June 8.
ChatGPT entered the top 10 most impersonated brands in phishing attacks according to Check Point research. Attackers are leveraging the brand's popularity to deceive users. This represents a growing threat vector email security professionals must monitor and defend against.
Russian hackers exploit a Zimbra zero-day vulnerability, sending "half-click" phishing emails requiring only message preview to compromise US and Ukraine targets. The state-sponsored group Laundry Bear leverages this technique for low-friction exploitation.
Russia-linked group Laundry Bear is exploiting Zimbra webmail with zero-click phishing attacks affecting users globally. U.S. and international partners issued an alert about the campaign targeting webmail accounts.
Cofense webinar highlights how AI is enabling more sophisticated, scalable phishing campaigns. Security teams must evolve detection strategies beyond individual emails to combat adaptive threat tactics.
German and US law enforcement dismantled Kratos, a major phishing kit designed to steal Microsoft 365 sessions and bypass MFA. An Indonesian developer was arrested. This takedown disrupts a widely-used criminal tool targeting email accounts globally.
PhantomEnigma campaign hijacks 20+ Brazilian government websites to distribute malware via trusted domains. Attackers compromised government mailboxes to send authenticated phishing emails bypassing SPF/DKIM/DMARC checks, targeting banking and public-sector organizations.
German law enforcement shut down Kratos, a widespread phishing-as-a-service kit, with support from US and Indonesian authorities. The operation targeted the infrastructure supporting one of the market's most dangerous PhaaS platforms and resulted in arrests. This disruption significantly impacts threat actors relying on Kratos for phishing campaigns.
APT42, an Iran-linked APT, is conducting sophisticated phishing campaigns against government and defense officials using AI-assisted research and realistic social engineering tactics, coupled with an updated TAMECAT malware variant designed for persistence and evasion.
Threat actors are conducting phishing campaigns impersonating Google Ads maintenance notices to steal user credentials. The attacks exploit familiarity and urgency by mimicking legitimate system notifications, targeting Google Ads Sync Account users with fake upgrade alerts.
Researchers at Rapid7 discovered an exposed server containing an AI-assisted phishing toolkit used in active malware campaigns. The toolkit, which includes lure templates and malware builders, was being deployed against Windows users in Mexico via WebDAV to deliver infostealers through spoofed government websites.
Attackers are using text salting to evade AI-powered email filters by hiding benign words in phishing emails. Barracuda detected over one million retail-themed phishing attacks using this technique since April, showing that traditional obfuscation methods remain effective against modern defenses.
Phishing emails with malicious TTF (TrueType Font) files attached are being used to deliver Windows malware. The attack disguises malware as legitimate business documents, exploiting users who trust font files. This represents a novel email-borne malware delivery technique targeting organizations.
Attackers are using text salting techniques to hide content in over 1 million phishing emails, exploiting weaknesses in AI-based email security filters. This attack method renders AI and large language models ineffective at detecting malicious messages, allowing them to bypass protection systems.