MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
ZeroTokens is a phishing platform enabling attackers to control victim sessions in real time, targeting 53 financial institutions. The tool allows dynamic attack steering, posing a significant threat to enterprise email security and authentication systems.
WhatsApp now supports multiple passkeys per account on iOS and Android, enabling phishing-resistant sign-ins. Over 1 billion users already rely on passkeys. This enhancement strengthens account security against credential-based attacks.
RecruitTrap campaigns are using mobile-optimized phishing pages to impersonate recruiters and steal corporate credentials. The scam targets enterprise employees through mobile devices, attempting to harvest login credentials at scale.
Mirage2FA, a phishing-as-a-service toolkit, compromised 4,500+ US and EU companies by abusing Microsoft 365 login flows to bypass 2FA. The campaign affected 48% of targeted email addresses. This directly impacts email security professionals defending against credential theft and account takeover attacks.
ReliaQuest confirmed that ShinyHunters hackers exploited a phishing-compromised employee account to access a dashboard, though the company states the impact was limited. This incident demonstrates the persistent threat of phishing targeting enterprise security firms.
Researchers discovered iAuthFlow V2, a phishing toolkit that registers attacker-controlled passkeys to maintain persistent access even after victims reset passwords or revoke active sessions. This represents a novel persistence mechanism that bypasses traditional account recovery measures.
Cybercriminals disguise malware as a Google Gemini installer to distribute Vidar stealer, targeting saved browser passwords and credentials. The attack exploits routine software searches rather than email phishing, demonstrating credential-theft risks from trojanized downloads.
Russian cyber-spy groups are conducting targeted phishing campaigns against European and US academics, aerospace, defense, and government officials, abusing OAuth to enhance their attacks. Google has identified three distinct groups running ongoing operations with fewer than 100 targets each.
Def Con attendees were targeted by a persistent phishing campaign after the conference. Huntress researchers documented the elaborate scam, highlighting how threat actors leverage event attendance to conduct targeted phishing attacks against security professionals.
A Chinese-nexus APT group linked to FamousSparrow is conducting spear-phishing campaigns targeting Central Asian organizations to deliver RATs, revealing China's strategic cyber operations in the region.
Mirage2FA, a Phishing-as-a-Service platform, enables attackers to bypass Microsoft 365 MFA by allowing users to complete normal login, then stealing authenticated sessions via an adversary-in-the-middle attack. Thousands of compromise events have occurred since late 2024.
Hackers use AI-generated voice calls paired with fake banking pages to bypass MFA and steal credentials from Mexican financial institutions. The Balonx Sistema campaign targets 20+ banks and has compromised 1,100+ accounts since October 2025 by requesting sensitive information during live phishing sessions.
Phishing tactics have evolved beyond payload-based detection toward AI-driven attacks where intent matters more than content. Traditional email defenses struggle as attackers increasingly use AI agents, requiring defenders to adopt new strategies.