MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
ThreatsDay roundup covers multiple attack vectors including CEO phishing kits, compromised Dropbox accounts, and OAuth-based attacks. Attackers leverage legitimate-looking communications and trusted platforms to gain access, exploiting human trust rather than technical vulnerabilities.
Attackers are exploiting ScreenConnect remote-access software to distribute worm-like malware across Windows networks via social engineering and phishing. Infected systems can spread payloads to connected machines without requiring individual phishing lures per victim, significantly expanding attack impact.
Hackers are using QR codes in phishing emails ("quishing") to steal login credentials by hiding malicious URLs in QR codes that appear less suspicious than text links. This tactic exploited people's trust in QR codes as routine shortcuts and reached record levels in H1 2026.
A phishing kit called Outsider generated 700 new pages after Google led a takedown effort, demonstrating the threat actor's resilience and ability to quickly recreate malicious infrastructure.
A phishing campaign using Canadian tax forms has expanded to 46 countries, with 45% of attacks targeting the US. The campaign delivers Remote Monitoring and Management (RMM) malware via deceptive tax documents, representing a significant threat to organizations globally.
Law enforcement and CrowdStrike disrupted the 23-year-old Sality peer-to-peer botnet affecting 15,000+ machines worldwide. The botnet distributed malware enabling credential theft, spam, proxying, and DDoS attacks. This takedown protects organizations from ongoing malware delivery and credential compromise risks.
FBI warns of phishing campaign targeting high-profile individuals and their contacts via commercial messaging apps. Attackers impersonate government officials and journalists to gain account access and steal sensitive data. The campaign demonstrates evolving social engineering tactics against prominent figures.
Cofense discusses its AI-powered phishing defense approach, emphasizing that effective anti-phishing solutions must handle threats that bypass initial defenses. The article addresses security leaders' focus on AI effectiveness rather than mere presence in phishing defense strategies.
Security Risk Advisors released SCALR AI, a free AI platform for security operations centers. The platform offers incident triage, threat hunting, and phishing detection capabilities deployed in customers' Azure environments.
A large-scale phishing campaign used SVG attachments disguised as voicemail notifications to evade email security controls. The attack targeted 5527 organizations with 26,000+ malicious messages, exploiting attachment-based delivery to breach email defenses.
A security researcher documents a polymorphic phishing page that dynamically changes appearance to evade detection. The attacker's code occasionally malfunctions, causing the phishing page to break. This demonstrates obfuscation techniques used in active phishing campaigns.
NovaCookies, a $320/month AitM phishing toolkit, abuses legitimate DocuSign notifications to redirect Microsoft 365 logins and steal authenticated sessions. The subscription-based platform poses significant risk to organizations by compromising M365 credentials through email-based social engineering attacks.
NovaCookies is a phishing-as-a-service kit enabling attackers to conduct adversary-in-the-middle attacks against Microsoft 365 users, stealing session cookies beyond credentials for $320/month. This lowers the attack complexity for email-based credential harvesting campaigns targeting enterprise cloud environments.
Criminals are using AI voice agents to impersonate Apple Support, targeting stolen-device owners to extract passcodes and 2FA codes via phishing calls. The AnonyMousKIT platform enables bypassing Apple's Activation Lock on stolen devices through a phishing-as-a-service model.