MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
Cisco disclosed an actively exploited zero-day in Secure Email Gateway (CVE-2026-76461) allowing remote unauthenticated command execution with root privileges. Attackers have already exploited this critical flaw before patching, potentially compromising email infrastructure and gateway integrity.
Black Axe cybercriminal gang members were extradited to the US to face charges related to romance scams, business email compromise (BEC), and money laundering. BEC attacks targeting financial transfers make this directly relevant to email security professionals.
Cisco Secure Email Gateway has a critical vulnerability (CVE-2026-76461) with a 9.8 CVSS score in AsyncOS email parsing logic. Unauthenticated remote attackers can exploit it for root command execution. Active exploitation in the wild poses immediate risk to email infrastructure.
Chinese hackers exploited Chrome and Windows zero-days in spear-phishing attacks against NGOs to deploy GRIMWEDGE, a JavaScript backdoor. The campaign leveraged recently patched vulnerabilities in a coordinated chain to compromise targets.
A zero-day root RCE vulnerability (CVE-2026-76461) in Cisco Secure Email Gateway is under active exploitation, allowing unauthenticated attackers to execute arbitrary commands with root privileges on affected systems.
Threat actors sent over one million phishing emails impersonating CEOs to target Microsoft cloud accounts using passkey-themed social engineering. Attackers exploited third-party email infrastructure to deliver fraud messages and breached cloud environments to exfiltrate data, posing a significant risk to organizations.
A threat actor generated 1 million personalized fraudulent emails in 3 days using AI, enabling attackers to scale phishing/BEC campaigns without sacrificing personalization. This significantly lowers the barrier for effective email-based fraud attacks targeting security defenders and their organizations.
Research analyzing 2.47 million simulated phishing attacks reveals that traditional click-based metrics don't effectively measure security awareness. Organizations should focus on credential compromise and incident reporting instead to better assess real vulnerability to phishing threats.
A roundup of cybersecurity news including an InjectEave attack bypassing phishing filters using invisible Unicode, a SIM swapper sentencing, and analysis of Chinese hacking group QTFY's military connections. Invisible Unicode techniques represent an emerging evasion threat for email security systems.
KnowBe4 researchers identified a phishing campaign exploiting Microsoft 365's Direct Send feature to deliver malicious emails, with attackers timing submissions during US Eastern business hours to maximize impact and detection evasion.
Phishing emails impersonating sexual misconduct allegations target universities, delivering fake Google Drive links that install Zoho RAT malware. Healthcare-linked institutions are primary targets. This demonstrates email's continued role as the primary attack vector for malware distribution.
Hackers compromised Brevo marketing platform and sent phishing emails to 347,000 Trezor users plus customers of BitBox and CoinTracking. The attack exploited a third-party service to distribute credential-theft emails targeting cryptocurrency users.
Attackers use Blob URLs and Microsoft Teams to host phishing pages directly in victims' browsers, evading detection. Campaigns begin with DocuSign-themed emails containing malicious calendar invitations that redirect through Microsoft OAuth and Teams endpoints, making the attack appear legitimate while bypassing security inspections.
Hackers are using passkey-themed phishing emails and social engineering to compromise Microsoft 365 accounts, bypassing MFA protections. Attackers pose as IT support via calls and texts, directing victims to fake sign-in pages. Compromised accounts facilitate further cloud data theft and Teams-based lure distribution.