MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
Russian state-sponsored attackers have exploited a Zimbra vulnerability for over a year, infecting targets automatically when viewing emails—without requiring clicks or file downloads. The campaign, attributed to Laundry Bear, affected government and commercial networks across the US, UK, and allies since July 2025.
A misconfigured WebDAV server exposed a malware factory containing over 1,000 attack files, including phishing lures, droppers, and malware variants. The GenAI-powered operation targeted Windows users with fake documents and malicious shortcuts. The discovery reveals detailed insights into attacker infrastructure and malware development practices.
Attackers distribute malicious Windows shortcuts via spam emails disguised as booking confirmations. Clicking the LNK file triggers PowerShell and Node.js to install a backdoor, enabling remote code execution and further system compromise.
Researchers discovered Avalon, a modular malware framework delivered via multi-stage phishing that bundles credential theft, lateral movement, and CrownX ransomware. It bypasses traditional security controls and poses a significant threat to organizations using email as an initial attack vector.
A new malware chain called VEIL#DROP uses Blogger platform and social engineering to deliver PureLogs stealer. Initial payloads distributed via spear-phishing or drive-by download attacks to compromise victims and steal information.
Black Basta ransomware syndicate operates like a sophisticated corporation, using advanced phishing and malware campaigns to target victims. The group's leaked internal communications reveal their evolution into organized extortion operations, relevant to understanding modern ransomware delivery mechanisms.
An exposed server revealed the Bissa Scanner platform, used for large-scale exploitation and credential harvesting across multiple victims. The operators leveraged AI tools like Claude Code and OpenAI to automate and refine their malicious collection pipeline, demonstrating sophisticated attack infrastructure.