MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
Researchers discovered Avalon, a modular malware framework delivered via multi-stage phishing that bundles credential theft, lateral movement, and CrownX ransomware. It bypasses traditional security controls and poses a significant threat to organizations using email as an initial attack vector.
A new malware chain called VEIL#DROP uses Blogger platform and social engineering to deliver PureLogs stealer. Initial payloads distributed via spear-phishing or drive-by download attacks to compromise victims and steal information.
Ousaban, a Brazilian banking trojan, targets Iberian bank users via phishing PDFs disguised as corrupted files. The malware verifies victim location in Spain/Portugal before deploying payload hidden in images to steal banking credentials.
Attackers are registering fake domains that LLMs hallucinate and suggest to users, then hosting phishing pages to capture traffic. This "phantom squatting" technique exploits AI's tendency to invent non-existent URLs, creating new phishing vectors that email users may encounter.