MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
Threat actors leveraged Claude and GPT tools to streamline attacks on government, financial, and transport networks in Latin America. The attacks combined AI-assisted techniques with conventional methods like phishing, malware, and legitimate tool abuse. This demonstrates how commercial AI accelerates existing intrusion workflows rather than introducing fundamentally new attack capabilities.
Threat actors impersonate university leaders in phishing emails falsely alleging sexual misconduct to trick victims into installing RATs. The social engineering lure exploits sensitive claims to enable malware delivery, providing attackers full system access and control.
Multiple cryptocurrency firms (Trezor, CoinTracking, BitBox) are warning customers of phishing emails following a breach at their shared email provider. Attackers compromised the provider's infrastructure, injecting malicious content into legitimate newsletters.
Attackers exploit Microsoft services and blob URLs to generate phishing pages directly in victims' browsers, evading detection of static websites. This stealthy technique makes blocking and analysis harder for email security defenders.
Attackers are leveraging multi-hop Google redirects to bypass security filters in phishing campaigns designed to steal credentials or deploy ScreenConnect malware. This technique exploits Google's trusted reputation to evade detection systems.
Autonomous AI agents were used by threat actors to compromise thousands of credentials in under six hours. Google's Threat Intelligence Group observed attackers leveraging a multi-agent framework for large-scale credential harvesting. This represents an escalation in AI-driven attacks that could impact email security defenses.
BigBear phishing crew harvested thousands of Microsoft 365 credentials and session cookies across hundreds of organizations. The operation, using Evilginx2-based phishing-as-a-service, captured hundreds of authenticated sessions capable of bypassing MFA. Researchers gained access to the attackers' admin panel, revealing unprecedented campaign details.
Researchers discovered a phishing service streaming real Google login pages to attackers in real-time, enabling interception of passwords, 2FA codes, and authenticated sessions. This sophisticated credential-theft technique poses significant risk to organizations relying on Google Workspace for email and collaboration.
Cybercriminals compromised Brazilian government servers to host phishing sites, leveraging a reverse-proxy network with gambling themes. A Chinese-language group is behind the campaign, targeting government and education infrastructure for malicious hosting.
CloudSEK discovered BigBear 2.0, a phishing-as-a-service campaign that has stolen over 5000 Microsoft credentials by targeting Microsoft 365 users. This threat directly affects email security as it leverages phishing to compromise email accounts and organizational infrastructure.
Article explains how exposed email addresses facilitate phishing and account takeover attacks, detailing threat mechanisms and defensive practices. Directly addresses email-security risks and protection strategies relevant to security professionals managing email infrastructure and user security.
Attackers are exploiting compromised ScreenConnect clients to distribute a four-stage VBScript malware payload to newly connected systems. Initial compromise vectors include tech-support scams, phishing emails with MSI installers, and fake applications. This affects organizations using ScreenConnect and represents a significant supply-chain-like threat via remote access software.
JSCeal, a sophisticated JavaScript malware, can steal session cookies to bypass Google Authentication and conduct surveillance. It features credential harvesting, traffic interception, and multiple obfuscation techniques. This poses significant risk to email users and organizations relying on email-based authentication.
Microsoft detected a massive phishing campaign using invisible Unicode characters (ASCII smuggling) to bypass email security filters, peaking at 2.37 million messages. Threat actors adapted AI-era techniques for traditional email phishing attacks. This highlights how obfuscation methods evolve to evade email defenses.
Microsoft warns of a high-volume phishing campaign exploiting invisible Unicode characters to evade email filters. Attackers split keywords like 'funding' across special characters, bypassing detection while remaining visible to users, directly threatening email security infrastructure.