MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
Microsoft is making passkeys the default authentication method in Entra ID and retiring SMS/voice authentication by September 2026, shifting toward phishing-resistant credentials. This impacts organizations relying on traditional MFA methods and requires migration planning to passkey-based authentication.
A 7-Zip vulnerability allows attackers to bypass Windows SmartScreen warnings by removing the Mark-of-the-Web indicator from extracted files. This is particularly dangerous in phishing campaigns where archives disguised as invoices or documents trick users into extraction, enabling malware execution without security prompts.
Researchers demonstrated how Microsoft Copilot in Microsoft 365 can be weaponized for business email compromise (BEC) and wire fraud. A single compromised employee account can escalate to CEO takeover and steal $250,000 with minimal attacker effort, posing significant risk to email security.
Phishing remains the primary breach vector, now enhanced by generative AI and account-takeover (AiTM) techniques that bypass email gateways and MFA. Top SOCs are adopting real-time behavioral detonation and threat intelligence to counter dynamic browser-based attacks that traditional email security cannot stop.
Operation BlueDash uses phishing emails falsely claiming document-sharing issues to trick users into installing a fake Microsoft Teams update, granting attackers dual remote-control capabilities. The campaign exploits email-based social engineering to deliver malware with multiple persistence mechanisms.
PhantomEnigma campaign hijacks 20+ Brazilian government websites to distribute malware via trusted domains. Attackers compromised government mailboxes to send authenticated phishing emails bypassing SPF/DKIM/DMARC checks, targeting banking and public-sector organizations.
APT42, an Iran-linked APT, is conducting sophisticated phishing campaigns against government and defense officials using AI-assisted research and realistic social engineering tactics, coupled with an updated TAMECAT malware variant designed for persistence and evasion.
A misconfigured WebDAV server exposed a malware factory containing over 1,000 attack files, including phishing lures, droppers, and malware variants. The GenAI-powered operation targeted Windows users with fake documents and malicious shortcuts. The discovery reveals detailed insights into attacker infrastructure and malware development practices.
Turkish banks face a large-scale fraud campaign using 8,400 phishing domains and 6,600 social media scam ads to steal credentials and money. Attackers impersonate trusted financial brands through fake websites and social ads targeting customers with credential theft and fake loan offers.
Attackers distribute malicious Windows shortcuts via spam emails disguised as booking confirmations. Clicking the LNK file triggers PowerShell and Node.js to install a backdoor, enabling remote code execution and further system compromise.
Threat group UNC066 has exploited Microsoft Entra passkey enrollment through phone-based phishing since April 2026, tricking employees into registering attacker-controlled passkeys to hijack enterprise accounts. The campaign combines social engineering with custom phishing kits targeting corporate credentials.
UNC6692 threat group uses Microsoft Teams impersonation in spam emails to trick victims into installing SNOW malware. Attackers pose as IT helpdesk staff, exploiting social engineering and trust in familiar tools to gain machine control. This campaign targets organizations via email-based initial contact.