MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
Russia's Star Blizzard APT group has abandoned ClickFix attacks for a new "RedFlick" phishing tactic targeting Ukrainian organizations. The campaign delivers the CosmicPulse backdoor to NGOs, think tanks, and journalists, representing an evolution in their phishing delivery methods and a direct threat to email security defenses.
Researchers discovered 'Salesbleed,' an attack that exploits Salesforce Agents to inject malicious instructions into Slack, enabling phishing attacks through trusted internal communication channels. This demonstrates how agentic AI systems can be manipulated to deliver harmful payloads across integrated business applications, posing risks to enterprise messaging security.
Attackers are poisoning AI chatbots by seeding the web with malicious links and data, which are then displayed in ChatGPT, Gemini, and Google AI responses. This technique facilitates mass disinformation and phishing campaigns targeting users who trust AI-generated answers.
Microsoft disrupted EvilTokens, a phishing-as-a-service platform targeting Microsoft 365 accounts, by seizing 50 websites and disabling 150+ domains. The action targets automated credential theft attacks leveraging device code authentication flows. This matters to security professionals managing email and cloud identity threats.
A threat actor generated 1 million personalized fraudulent emails in 3 days using AI, enabling attackers to scale phishing/BEC campaigns without sacrificing personalization. This significantly lowers the barrier for effective email-based fraud attacks targeting security defenders and their organizations.
Attackers are leveraging multi-hop Google redirects to bypass security filters in phishing campaigns designed to steal credentials or deploy ScreenConnect malware. This technique exploits Google's trusted reputation to evade detection systems.
Cybercriminals compromised Brazilian government servers to host phishing sites, leveraging a reverse-proxy network with gambling themes. A Chinese-language group is behind the campaign, targeting government and education infrastructure for malicious hosting.
NovaCookies is a phishing-as-a-service kit enabling attackers to conduct adversary-in-the-middle attacks against Microsoft 365 users, stealing session cookies beyond credentials for $320/month. This lowers the attack complexity for email-based credential harvesting campaigns targeting enterprise cloud environments.
A Chinese-nexus APT group linked to FamousSparrow is conducting spear-phishing campaigns targeting Central Asian organizations to deliver RATs, revealing China's strategic cyber operations in the region.
Device code phishing attacks surged 1,500% in 2026, while vishing (voice phishing) doubled. These social engineering techniques bypass traditional security controls and minimize forensic traces.
Russian hackers exploit a Zimbra zero-day vulnerability, sending "half-click" phishing emails requiring only message preview to compromise US and Ukraine targets. The state-sponsored group Laundry Bear leverages this technique for low-friction exploitation.
Attackers are combining evasion tactics including fileless techniques and loaders to deploy RATs and stealers in BEC phishing campaigns. This sophisticated approach achieves low detection rates, making it harder for email security systems to catch these threats before they reach users.
Attackers are using text salting techniques to hide content in over 1 million phishing emails, exploiting weaknesses in AI-based email security filters. This attack method renders AI and large language models ineffective at detecting malicious messages, allowing them to bypass protection systems.
An open-source AI system called 'ScamBuster' uses victim personas to engage phishing attackers, enabling organizations and law enforcement to gather intelligence on criminal operations. This defensive tool helps turn the tables on email scammers by collecting operational data.
A phishing campaign impersonating job opportunities from major brands targets marketing professionals to steal their Google account credentials using nested redirects and evasion techniques.