MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
Article describes a 3-step approach for SOC teams to investigate phishing alerts more efficiently, addressing challenges like encrypted traffic and obfuscation techniques that slow analysis and response.
Article discusses how US SOCs and MSSPs can leverage threat intelligence to detect phishing infrastructure earlier by understanding the complex network of domains, compromised sites, redirectors, and cloud services attackers use behind phishing links.
Attackers are conducting a widespread SMS phishing campaign impersonating T-Mobile, claiming loyalty points are expiring to trick users into visiting malicious sites that steal login credentials, personal data, and payment information. The campaign began in May 2026 and persists through continuous variations.
BlackHatSect0r used a DeepSeek-powered AI agent to automate credential harvesting and phishing attacks, extracting 16,834 credentials through exposed security gaps. The exposed server revealed phishing tools and a custom DXSCAN platform, demonstrating how AI accelerates credential theft at scale.
A smishing campaign intercepts victims' card details and OTPs in real-time through fake payment pages impersonating official services. Attackers use shortened links and urgency tactics to trick users into entering sensitive information that criminals observe live.
PAPERMILL campaign uses phishing emails with fake tax-audit notices and Notepad++ signed binaries to deliver VenomRAT malware. Disk-image attachments bypass security email checks (SPF/DKIM/DMARC) and Windows warnings, targeting unsuspecting users with trojan deployment.
Attackers use Blob URLs and Microsoft Teams to host phishing pages directly in victims' browsers, evading detection. Campaigns begin with DocuSign-themed emails containing malicious calendar invitations that redirect through Microsoft OAuth and Teams endpoints, making the attack appear legitimate while bypassing security inspections.
Hackers are using passkey-themed phishing emails and social engineering to compromise Microsoft 365 accounts, bypassing MFA protections. Attackers pose as IT support via calls and texts, directing victims to fake sign-in pages. Compromised accounts facilitate further cloud data theft and Teams-based lure distribution.
Threat actors leveraged Claude and GPT tools to streamline attacks on government, financial, and transport networks in Latin America. The attacks combined AI-assisted techniques with conventional methods like phishing, malware, and legitimate tool abuse. This demonstrates how commercial AI accelerates existing intrusion workflows rather than introducing fundamentally new attack capabilities.
Hackers are using QR codes in phishing emails ("quishing") to steal login credentials by hiding malicious URLs in QR codes that appear less suspicious than text links. This tactic exploited people's trust in QR codes as routine shortcuts and reached record levels in H1 2026.
Mirage2FA, a Phishing-as-a-Service platform, enables attackers to bypass Microsoft 365 MFA by allowing users to complete normal login, then stealing authenticated sessions via an adversary-in-the-middle attack. Thousands of compromise events have occurred since late 2024.
Hackers use AI-generated voice calls paired with fake banking pages to bypass MFA and steal credentials from Mexican financial institutions. The Balonx Sistema campaign targets 20+ banks and has compromised 1,100+ accounts since October 2025 by requesting sensitive information during live phishing sessions.