MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
Attackers are exploiting compromised ScreenConnect clients to distribute a four-stage VBScript malware payload to newly connected systems. Initial compromise vectors include tech-support scams, phishing emails with MSI installers, and fake applications. This affects organizations using ScreenConnect and represents a significant supply-chain-like threat via remote access software.
JSCeal, a sophisticated JavaScript malware, can steal session cookies to bypass Google Authentication and conduct surveillance. It features credential harvesting, traffic interception, and multiple obfuscation techniques. This poses significant risk to email users and organizations relying on email-based authentication.
Researchers discovered Avalon, a modular malware framework delivered via multi-stage phishing that bundles credential theft, lateral movement, and CrownX ransomware. It bypasses traditional security controls and poses a significant threat to organizations using email as an initial attack vector.
A new malware chain called VEIL#DROP uses Blogger platform and social engineering to deliver PureLogs stealer. Initial payloads distributed via spear-phishing or drive-by download attacks to compromise victims and steal information.