MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
Threat actors are using invitation-themed phishing emails spoofing legitimate event platforms like Punchbowl and Evite to steal credentials and install malware. Cofense Intelligence reports sustained campaigns targeting users with fake login pages and remote access tools. This attack vector remains effective because users trust familiar invitation platforms.
Cofense webinar highlights how AI is enabling more sophisticated, scalable phishing campaigns. Security teams must evolve detection strategies beyond individual emails to combat adaptive threat tactics.
Threat actors are conducting phishing campaigns impersonating Google Ads maintenance notices to steal user credentials. The attacks exploit familiarity and urgency by mimicking legitimate system notifications, targeting Google Ads Sync Account users with fake upgrade alerts.
Finance-themed phishing campaigns are evolving from urgent, pressure-driven tactics to mundane process-oriented messaging that mimics routine financial workflows. This shift makes phishing emails harder to detect and may indicate broader adoption among threat actors targeting organizations.
Threat actors are shifting from generic phishing campaigns to platform-aware attacks that adapt malware delivery based on the victim's device, browser, and environment. This evolution targets Windows, macOS, and other platforms with selective credential phishing, RATs, or malware payloads, requiring defenders to strengthen detection across multiple endpoints.
AI-powered phishing attacks now evade traditional email security tools through polymorphic campaigns that continuously evolve. Organizations must adopt board-level cyber resilience strategies beyond IT-focused security gateways and filters to combat adaptive threats.
Cofense webinar discusses how AI is enabling attackers to scale phishing attacks more efficiently. Security leaders must adapt their defenses as phishing becomes a more sophisticated, AI-driven threat requiring modern mitigation strategies.
Cofense discovered a phishing campaign using FIFA World Cup 2026 lures to deliver Voidrift malware. Emails are highly personalized with recipient and company details, indicating extensive reconnaissance. The campaign demonstrates sophisticated social engineering tactics targeting organizations.
A multi-stage phishing campaign spoofs IRS communications to lure victims with fraudulent tax refunds tied to Elon Musk and cryptocurrency, stealing credentials and personal information for identity theft and financial fraud.
Modern phishing attacks using AI-generated, polymorphic messages increasingly look legitimate and avoid static detection, requiring security leaders to move beyond prevention-focused defenses to adopt new strategies for detecting and responding to sophisticated social engineering.
Cofense discusses the evolving email threat landscape, including AI-enabled phishing, BEC, and ransomware, while highlighting how cybersecurity teams must balance sophisticated threats with increasing regulatory compliance requirements.
The article critiques 'spot the phish' email security training, arguing it's outdated because modern phishing attacks lack obvious visual red flags. As phishing techniques become more sophisticated, traditional user-awareness models fail to protect organizations effectively.
Threat actors impersonate Amazon with fake security alerts and lookalike domains to deliver ClickFix malware that installs HarborWatch Agent, a custom monitoring RAT. The campaign uses social engineering and fake verification tactics to trick users into self-infection via email.
AI-powered phishing attacks now bypass traditional red flags by generating grammatically correct, contextually relevant emails tailored to specific targets. Classic awareness training focused on poor grammar and generic greetings is insufficient against sophisticated AI-crafted messages. Security professionals must adapt detection and training strategies accordingly.