MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
A phishing campaign disguises a Lua-based loader as a TrueType font file to distribute remote access trojans and information-stealing malware. The attack uses email-based delivery to compromise targets globally.
OkoBot malware framework targets hardware wallet users by injecting phishing prompts into legitimate Ledger and Trezor desktop applications to steal recovery phrases. Active since April 2025, the malware exploits trust in wallet software to compromise cryptocurrency assets on infected Windows systems.
A six-month phishing campaign leveraged seasonal eCard lures to deliver legitimate remote management tools to victims. The attack used social engineering via email to compromise targets. Email security professionals should monitor for eCard-themed phishing and suspicious RMM tool deployments.
Sophos research reveals compromised credentials have become the primary ransomware entry point, surpassing software vulnerabilities. Phishing and brute force attacks enable attackers to gain initial access before deploying ransomware, affecting organizations across sectors.
Finance-themed phishing campaigns are evolving from urgent, pressure-driven tactics to mundane process-oriented messaging that mimics routine financial workflows. This shift makes phishing emails harder to detect and may indicate broader adoption among threat actors targeting organizations.
Turkish banks face a large-scale fraud campaign using 8,400 phishing domains and 6,600 social media scam ads to steal credentials and money. Attackers impersonate trusted financial brands through fake websites and social ads targeting customers with credential theft and fake loan offers.
A misconfigured open directory exposed infrastructure details for three phishing operators using Evilginx, a tool that bypasses multi-factor authentication. This reveals active phishing campaigns targeting email credentials and MFA tokens, directly impacting email security defenses.
Forg365, a phishing-as-a-service platform sold on Telegram for $400/month, targets Microsoft 365 accounts using device code phishing, AitM session theft, and AI-generated lures, followed by mailbox compromise. This threatens organizations relying on Microsoft 365 email and poses significant risk to email security defenders.
An open-source AI system called 'ScamBuster' uses victim personas to engage phishing attackers, enabling organizations and law enforcement to gather intelligence on criminal operations. This defensive tool helps turn the tables on email scammers by collecting operational data.
A misconfigured public web server exposed an active Evilginx phishing operation targeting Microsoft 365, revealing the attacker's toolkit and leading to discovery of two additional related operations. This demonstrates how poor operational security compromises sophisticated phishing infrastructure.
Okta reports vishing attacks targeting Microsoft 365 customers, with attackers using phone calls to direct victims to fake Microsoft Entra ID login pages. This phishing technique aims to steal credentials from a widely-used enterprise authentication system.
Attackers are using fake Microsoft Entra passkey enrollment prompts via voice-based phishing to compromise Microsoft 365 accounts across multiple sectors. The threat actor O-UNC-066 deploys a panel-controlled phishing kit targeting passkey enrollment, leading to data extortion attacks.
Security researchers identified a phishing technique using HTML comment stuffing to evade AI-based email detection systems. This method obscures phishing content within HTML comments, representing an evolving evasion tactic that email security professionals should monitor for detection bypass attempts.
Threat group UNC066 has exploited Microsoft Entra passkey enrollment through phone-based phishing since April 2026, tricking employees into registering attacker-controlled passkeys to hijack enterprise accounts. The campaign combines social engineering with custom phishing kits targeting corporate credentials.
UNC6692 threat group uses Microsoft Teams impersonation in spam emails to trick victims into installing SNOW malware. Attackers pose as IT helpdesk staff, exploiting social engineering and trust in familiar tools to gain machine control. This campaign targets organizations via email-based initial contact.