MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
Phishing campaigns impersonate meeting invitations and software updates to trick users into installing MSP360 RMM software, which attackers then abuse to deploy ScreenConnect for dual-RMM control. This gives threat actors persistent remote access to compromised systems, affecting organizations relying on RMM tools.
A US-focused phishing campaign targets C-suite executives, stealing Microsoft 365 sessions and deploying remote-access tools (RMM) for persistent compromise. Technology, manufacturing, government, and consulting sectors are heavily affected. This escalates phishing from credential theft to enterprise-wide account takeover.
Microsoft disabled EvilTokens, an AI-powered device-code phishing service responsible for compromising approximately 12,000 inboxes. The takedown was coordinated with law enforcement and multiple tech companies. This represents a significant disruption to a major phishing-as-a-service operation targeting email accounts.
SideCopy, an India-focused threat actor, has expanded targeting to academic institutions via spear-phishing campaigns using ReverseRAT malware. The group leverages mshta.exe abuse to execute malicious scripts and bypass security controls, broadening from government to education sector targets.
RatHat is a China-based Android malware distributed via smishing and malvertising that uses AI for device control and persists through ADB abuse. It targets mobile devices with SMS phishing and fake app downloads, relevant to email security professionals monitoring phishing campaign vectors.
N0va phishkit targets US and EU businesses with sophisticated phishing campaigns impersonating trusted services to compromise legitimate accounts. Attackers bypass malware detection by leveraging valid credentials to access sensitive data and business systems, posing significant risk to organizations.
Cisco Secure Email Gateway has a critical vulnerability (CVE-2026-76461) with a 9.8 CVSS score in AsyncOS email parsing logic. Unauthenticated remote attackers can exploit it for root command execution. Active exploitation in the wild poses immediate risk to email infrastructure.
Chinese hackers exploited Chrome and Windows zero-days in spear-phishing attacks against NGOs to deploy GRIMWEDGE, a JavaScript backdoor. The campaign leveraged recently patched vulnerabilities in a coordinated chain to compromise targets.
Threat actors sent over one million phishing emails impersonating CEOs to target Microsoft cloud accounts using passkey-themed social engineering. Attackers exploited third-party email infrastructure to deliver fraud messages and breached cloud environments to exfiltrate data, posing a significant risk to organizations.
Autonomous AI agents were used by threat actors to compromise thousands of credentials in under six hours. Google's Threat Intelligence Group observed attackers leveraging a multi-agent framework for large-scale credential harvesting. This represents an escalation in AI-driven attacks that could impact email security defenses.
Attackers are exploiting compromised ScreenConnect clients to distribute a four-stage VBScript malware payload to newly connected systems. Initial compromise vectors include tech-support scams, phishing emails with MSI installers, and fake applications. This affects organizations using ScreenConnect and represents a significant supply-chain-like threat via remote access software.
JSCeal, a sophisticated JavaScript malware, can steal session cookies to bypass Google Authentication and conduct surveillance. It features credential harvesting, traffic interception, and multiple obfuscation techniques. This poses significant risk to email users and organizations relying on email-based authentication.
Microsoft warns of a high-volume phishing campaign exploiting invisible Unicode characters to evade email filters. Attackers split keywords like 'funding' across special characters, bypassing detection while remaining visible to users, directly threatening email security infrastructure.
ThreatsDay roundup covers multiple attack vectors including CEO phishing kits, compromised Dropbox accounts, and OAuth-based attacks. Attackers leverage legitimate-looking communications and trusted platforms to gain access, exploiting human trust rather than technical vulnerabilities.