MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
Microsoft and partners disrupted EvilTokens, a phishing-as-a-service platform that compromised over 12,000 email inboxes across 10,000+ organizations. The operation seized 50 websites and disabled 175+ domains used for credential theft and financial fraud attacks.
Cisco disclosed an actively exploited zero-day in Secure Email Gateway (CVE-2026-76461) allowing remote unauthenticated command execution with root privileges. Attackers have already exploited this critical flaw before patching, potentially compromising email infrastructure and gateway integrity.
FBI warns of phishing campaign targeting high-profile individuals and their contacts via commercial messaging apps. Attackers impersonate government officials and journalists to gain account access and steal sensitive data. The campaign demonstrates evolving social engineering tactics against prominent figures.
Researchers discovered ARToken, a business email compromise-as-a-service platform affiliated with EvilTokens phishing operation. The toolkit is designed to bypass MFA and compromise Microsoft 365 accounts, representing an advanced threat targeting organizations.
Black Basta ransomware syndicate operates like a sophisticated corporation, using advanced phishing and malware campaigns to target victims. The group's leaked internal communications reveal their evolution into organized extortion operations, relevant to understanding modern ransomware delivery mechanisms.