MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
Brazilian banking trojan Ousaban is actively targeting Spain and Portugal through phishing campaigns. FortiGuard has identified the threat, which uses email as a delivery vector to compromise financial accounts in the region.
Attackers are registering fake domains that LLMs hallucinate and suggest to users, then hosting phishing pages to capture traffic. This "phantom squatting" technique exploits AI's tendency to invent non-existent URLs, creating new phishing vectors that email users may encounter.
A phishing campaign targeting MetaMask cryptocurrency wallet users was detected. The attack uses alternative authentication methods instead of traditional credential theft, demonstrating evolving phishing tactics that security professionals should recognize.
Threat actors are shifting from generic phishing campaigns to platform-aware attacks that adapt malware delivery based on the victim's device, browser, and environment. This evolution targets Windows, macOS, and other platforms with selective credential phishing, RATs, or malware payloads, requiring defenders to strengthen detection across multiple endpoints.
EvilTokens is a phishing attack that hides account takeover indicators until browser execution, leaving SOCs with limited visibility. Enterprise teams need enhanced monitoring to validate threats faster and reduce account compromise risk.
Proofpoint discusses device code phishing attacks where attackers bypass authentication mechanisms using OAuth device flows. This threat targets users' authentication credentials and could enable account compromise, making it relevant for email security professionals handling credential-based threats.
Hackers sent phishing emails to Japanese hotels partnered with Booking.com in May, distributing malware hosted on blockchain networks. The campaign targeted accommodation partners through credential-stealing phishing, enabling unauthorized access to booking accounts and guest data.
The FBI warns that Russian intelligence actors are conducting phishing campaigns to steal Signal backup encryption keys. This targets users' end-to-end encrypted communications. Email security professionals should monitor for phishing emails luring users to compromise their encrypted messaging credentials.
AI-powered phishing attacks now evade traditional email security tools through polymorphic campaigns that continuously evolve. Organizations must adopt board-level cyber resilience strategies beyond IT-focused security gateways and filters to combat adaptive threats.
A Canadian health board conducted a phishing awareness test on staff using a fake vacation day offer, which sparked backlash for its inappropriate theme. The organization apologized for the social engineering exercise designed to test employee security awareness.
Cofense discovered a phishing campaign using FIFA World Cup 2026 lures to deliver Voidrift malware. Emails are highly personalized with recipient and company details, indicating extensive reconnaissance. The campaign demonstrates sophisticated social engineering tactics targeting organizations.
Cofense webinar discusses how AI is enabling attackers to scale phishing attacks more efficiently. Security leaders must adapt their defenses as phishing becomes a more sophisticated, AI-driven threat requiring modern mitigation strategies.
A serverless phishing kit named GitBait exploits GitHub Pages and SheetBest API to target Mexican banks and steal credentials. The kit leverages hosting and data aggregation services to facilitate credential theft at scale.
A multi-stage phishing campaign spoofs IRS communications to lure victims with fraudulent tax refunds tied to Elon Musk and cryptocurrency, stealing credentials and personal information for identity theft and financial fraud.
Modern phishing attacks using AI-generated, polymorphic messages increasingly look legitimate and avoid static detection, requiring security leaders to move beyond prevention-focused defenses to adopt new strategies for detecting and responding to sophisticated social engineering.