MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
Threat actors are shifting from generic phishing campaigns to platform-aware attacks that adapt malware delivery based on the victim's device, browser, and environment. This evolution targets Windows, macOS, and other platforms with selective credential phishing, RATs, or malware payloads, requiring defenders to strengthen detection across multiple endpoints.
EvilTokens is a phishing attack that hides account takeover indicators until browser execution, leaving SOCs with limited visibility. Enterprise teams need enhanced monitoring to validate threats faster and reduce account compromise risk.
Proofpoint discusses device code phishing attacks where attackers bypass authentication mechanisms using OAuth device flows. This threat targets users' authentication credentials and could enable account compromise, making it relevant for email security professionals handling credential-based threats.
Hackers sent phishing emails to Japanese hotels partnered with Booking.com in May, distributing malware hosted on blockchain networks. The campaign targeted accommodation partners through credential-stealing phishing, enabling unauthorized access to booking accounts and guest data.
Black Basta ransomware syndicate operates like a sophisticated corporation, using advanced phishing and malware campaigns to target victims. The group's leaked internal communications reveal their evolution into organized extortion operations, relevant to understanding modern ransomware delivery mechanisms.
The FBI warns that Russian intelligence actors are conducting phishing campaigns to steal Signal backup encryption keys. This targets users' end-to-end encrypted communications. Email security professionals should monitor for phishing emails luring users to compromise their encrypted messaging credentials.
AI-powered phishing attacks now evade traditional email security tools through polymorphic campaigns that continuously evolve. Organizations must adopt board-level cyber resilience strategies beyond IT-focused security gateways and filters to combat adaptive threats.
A Canadian health board conducted a phishing awareness test on staff using a fake vacation day offer, which sparked backlash for its inappropriate theme. The organization apologized for the social engineering exercise designed to test employee security awareness.
Cofense discovered a phishing campaign using FIFA World Cup 2026 lures to deliver Voidrift malware. Emails are highly personalized with recipient and company details, indicating extensive reconnaissance. The campaign demonstrates sophisticated social engineering tactics targeting organizations.
Cofense webinar discusses how AI is enabling attackers to scale phishing attacks more efficiently. Security leaders must adapt their defenses as phishing becomes a more sophisticated, AI-driven threat requiring modern mitigation strategies.
A serverless phishing kit named GitBait exploits GitHub Pages and SheetBest API to target Mexican banks and steal credentials. The kit leverages hosting and data aggregation services to facilitate credential theft at scale.
A multi-stage phishing campaign spoofs IRS communications to lure victims with fraudulent tax refunds tied to Elon Musk and cryptocurrency, stealing credentials and personal information for identity theft and financial fraud.
Modern phishing attacks using AI-generated, polymorphic messages increasingly look legitimate and avoid static detection, requiring security leaders to move beyond prevention-focused defenses to adopt new strategies for detecting and responding to sophisticated social engineering.
Interpol dismantled SniperDz, a decade-old phishing-as-a-service platform exposed by Group-IB. The operation provided phishing infrastructure to cybercriminals targeting organizations globally. This takedown is significant for email security professionals as it disrupts a major phishing distribution network.
Menlo Security research reveals that traditional cybersecurity tools fail to detect 20% of browser-based phishing attacks, leaving enterprises vulnerable as applications shift to browser-based platforms.