MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
Phishing campaigns impersonate meeting invitations and software updates to trick users into installing MSP360 RMM software, which attackers then abuse to deploy ScreenConnect for dual-RMM control. This gives threat actors persistent remote access to compromised systems, affecting organizations relying on RMM tools.
A US-focused phishing campaign targets C-suite executives, stealing Microsoft 365 sessions and deploying remote-access tools (RMM) for persistent compromise. Technology, manufacturing, government, and consulting sectors are heavily affected. This escalates phishing from credential theft to enterprise-wide account takeover.
Microsoft disabled EvilTokens, an AI-powered device-code phishing service responsible for compromising approximately 12,000 inboxes. The takedown was coordinated with law enforcement and multiple tech companies. This represents a significant disruption to a major phishing-as-a-service operation targeting email accounts.
SideCopy, an India-focused threat actor, has expanded targeting to academic institutions via spear-phishing campaigns using ReverseRAT malware. The group leverages mshta.exe abuse to execute malicious scripts and bypass security controls, broadening from government to education sector targets.
RatHat is a China-based Android malware distributed via smishing and malvertising that uses AI for device control and persists through ADB abuse. It targets mobile devices with SMS phishing and fake app downloads, relevant to email security professionals monitoring phishing campaign vectors.
N0va phishkit targets US and EU businesses with sophisticated phishing campaigns impersonating trusted services to compromise legitimate accounts. Attackers bypass malware detection by leveraging valid credentials to access sensitive data and business systems, posing significant risk to organizations.
Chinese hackers exploited Chrome and Windows zero-days in spear-phishing attacks against NGOs to deploy GRIMWEDGE, a JavaScript backdoor. The campaign leveraged recently patched vulnerabilities in a coordinated chain to compromise targets.
Threat actors sent over one million phishing emails impersonating CEOs to target Microsoft cloud accounts using passkey-themed social engineering. Attackers exploited third-party email infrastructure to deliver fraud messages and breached cloud environments to exfiltrate data, posing a significant risk to organizations.
Microsoft warns of a high-volume phishing campaign exploiting invisible Unicode characters to evade email filters. Attackers split keywords like 'funding' across special characters, bypassing detection while remaining visible to users, directly threatening email security infrastructure.
ThreatsDay roundup covers multiple attack vectors including CEO phishing kits, compromised Dropbox accounts, and OAuth-based attacks. Attackers leverage legitimate-looking communications and trusted platforms to gain access, exploiting human trust rather than technical vulnerabilities.
A phishing campaign using Canadian tax forms has expanded to 46 countries, with 45% of attacks targeting the US. The campaign delivers Remote Monitoring and Management (RMM) malware via deceptive tax documents, representing a significant threat to organizations globally.
NovaCookies, a $320/month AitM phishing toolkit, abuses legitimate DocuSign notifications to redirect Microsoft 365 logins and steal authenticated sessions. The subscription-based platform poses significant risk to organizations by compromising M365 credentials through email-based social engineering attacks.
Criminals are using AI voice agents to impersonate Apple Support, targeting stolen-device owners to extract passcodes and 2FA codes via phishing calls. The AnonyMousKIT platform enables bypassing Apple's Activation Lock on stolen devices through a phishing-as-a-service model.
WhatsApp now supports multiple passkeys per account on iOS and Android, enabling phishing-resistant sign-ins. Over 1 billion users already rely on passkeys. This enhancement strengthens account security against credential-based attacks.