MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
37 articles from Infosecurity Magazine in Phishing
Security researchers at EfficientIP identified phishing domains impersonating AliExpress before registration completion, demonstrating proactive threat detection capabilities. This highlights the vulnerability of popular e-commerce brands to phishing attacks and the importance of domain monitoring for email security.
Revolut customers are experiencing a surge in phishing attacks following a recent data breach. Attackers are leveraging stolen customer data to craft convincing phishing messages. This represents a significant risk for email-based credential theft and fraud targeting financial services users.
KnowBe4 researchers identified a phishing campaign exploiting Microsoft 365's Direct Send feature to deliver malicious emails, with attackers timing submissions during US Eastern business hours to maximize impact and detection evasion.
CloudSEK discovered BigBear 2.0, a phishing-as-a-service campaign that has stolen over 5000 Microsoft credentials by targeting Microsoft 365 users. This threat directly affects email security as it leverages phishing to compromise email accounts and organizational infrastructure.
A phishing kit called Outsider generated 700 new pages after Google led a takedown effort, demonstrating the threat actor's resilience and ability to quickly recreate malicious infrastructure.
A large-scale phishing campaign used SVG attachments disguised as voicemail notifications to evade email security controls. The attack targeted 5527 organizations with 26,000+ malicious messages, exploiting attachment-based delivery to breach email defenses.
ZeroTokens is a phishing platform enabling attackers to control victim sessions in real time, targeting 53 financial institutions. The tool allows dynamic attack steering, posing a significant threat to enterprise email security and authentication systems.
RecruitTrap campaigns are using mobile-optimized phishing pages to impersonate recruiters and steal corporate credentials. The scam targets enterprise employees through mobile devices, attempting to harvest login credentials at scale.
Def Con attendees were targeted by a persistent phishing campaign after the conference. Huntress researchers documented the elaborate scam, highlighting how threat actors leverage event attendance to conduct targeted phishing attacks against security professionals.
Cybercriminals are running a phishing campaign impersonating Bank of America to distribute malware that installs ScreenConnect remote access tools. The scam enables attackers to gain persistent system access and control compromised machines.
Adversary-in-the-Middle (AiTM) phishing has become the leading initial access vector for law firms, accounting for 56% of threats. This technique bypasses multi-factor authentication by intercepting credentials in real-time, posing severe risks to organizations handling sensitive client data.
Attackers used Teams-themed phishing to abuse Microsoft's legitimate login pages rather than hosting fake ones, making detection harder. Check Point researchers documented this campaign targeting users. This represents an evolution in phishing tactics that security professionals need to identify and defend against.
LogoKit phishing kit now generates victim-specific phishing pages using real-time screenshots of target websites, making phishing attacks more convincing and harder to detect. This advancement increases phishing campaign effectiveness against email recipients.
Cisco Talos analysis reveals phishing continues as the leading entry point for cyber-attacks, with hackers refining evasion techniques. This trend underscores the persistent threat of phishing against organizations and the need for robust email security defenses.
ChatGPT entered the top 10 most impersonated brands in phishing attacks according to Check Point research. Attackers are leveraging the brand's popularity to deceive users. This represents a growing threat vector email security professionals must monitor and defend against.