MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
Russian APT Star Blizzard conducts phishing campaigns using the RedFlick infection chain to deploy the CosmicPulse backdoor. This represents a broader attack capability for the state-sponsored group targeting enterprise environments.
Three vulnerabilities in Salesforce Agentforce allowed attackers to hijack trusted agents and steal data. The flaws enabled zero-click phishing attacks, impacting organizations using Salesforce's AI agent platform for customer interactions.
Microsoft disrupted EvilTokens, an AI-powered phishing platform that automated social engineering attacks and target selection. The platform represented an escalated threat using machine learning across the entire attack chain, now taken offline by Microsoft's intervention.
Research analyzing 2.47 million simulated phishing attacks reveals that traditional click-based metrics don't effectively measure security awareness. Organizations should focus on credential compromise and incident reporting instead to better assess real vulnerability to phishing threats.
A roundup of cybersecurity news including an InjectEave attack bypassing phishing filters using invisible Unicode, a SIM swapper sentencing, and analysis of Chinese hacking group QTFY's military connections. Invisible Unicode techniques represent an emerging evasion threat for email security systems.
Hackers compromised Brevo marketing platform and sent phishing emails to 347,000 Trezor users plus customers of BitBox and CoinTracking. The attack exploited a third-party service to distribute credential-theft emails targeting cryptocurrency users.
Attackers exploit Microsoft services and blob URLs to generate phishing pages directly in victims' browsers, evading detection of static websites. This stealthy technique makes blocking and analysis harder for email security defenders.
ReliaQuest confirmed that ShinyHunters hackers exploited a phishing-compromised employee account to access a dashboard, though the company states the impact was limited. This incident demonstrates the persistent threat of phishing targeting enterprise security firms.
Researchers discovered iAuthFlow V2, a phishing toolkit that registers attacker-controlled passkeys to maintain persistent access even after victims reset passwords or revoke active sessions. This represents a novel persistence mechanism that bypasses traditional account recovery measures.
IEH Corporation suffered a mailbox breach through phishing, alongside notable incidents including a QuickFox VPN supply chain attack and restrictions on Chinese data center technology. These stories highlight ongoing threats to infrastructure and email systems.
Okta reports vishing attacks targeting Microsoft 365 customers, with attackers using phone calls to direct victims to fake Microsoft Entra ID login pages. This phishing technique aims to steal credentials from a widely-used enterprise authentication system.
A webinar discussing the limitations of email-layer defenses against modern phishing attacks. It addresses why organizations struggle to prevent phishing and suggests need for broader security approaches beyond traditional email filtering.