MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
Researchers demonstrated how Microsoft Copilot in Microsoft 365 can be weaponized for business email compromise (BEC) and wire fraud. A single compromised employee account can escalate to CEO takeover and steal $250,000 with minimal attacker effort, posing significant risk to email security.
Attackers are combining evasion tactics including fileless techniques and loaders to deploy RATs and stealers in BEC phishing campaigns. This sophisticated approach achieves low detection rates, making it harder for email security systems to catch these threats before they reach users.
Researchers discovered ARToken, a business email compromise-as-a-service platform affiliated with EvilTokens phishing operation. The toolkit is designed to bypass MFA and compromise Microsoft 365 accounts, representing an advanced threat targeting organizations.