MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
This week in email security
AI briefing · 2026-08-30
Phishing-as-a-service kits and credential-theft campaigns surge across Microsoft 365 and mobile
Mirage2FA and NovaCookies represent a dangerous ecosystem shift: affordable subscription-based phishing toolkits ($320/month) now enable mass compromise of Microsoft 365 accounts by abusing legitimate login flows and stealing session cookies beyond credentials.
SVG attachment evasion, polymorphic phishing pages, and real-time session steering (ZeroTokens) show attackers evolving detection-bypass techniques faster than defenses, with individual campaigns targeting thousands of organizations and compromising thousands of accounts.
Mobile-optimized phishing (RecruitTrap) and AI voice impersonation (AnonyMousKIT targeting Apple users) extend threats beyond email into channels where defenders have less visibility and users expect less scrutiny.
Open-source supply-chain abuse via npm packages hosting fake CAPTCHAs demonstrates attackers repurposing legitimate infrastructure as free phishing hosting, expanding attack surface into developer ecosystems.
WhatsApp's passkey support on over 1 billion accounts signals growing availability of phishing-resistant authentication, creating defender opportunity to push adoption where phishing-as-a-service remains rampant.
A large-scale phishing campaign used SVG attachments disguised as voicemail notifications to evade email security controls. The attack targeted 5527 organizations with 26,000+ malicious messages, exploiting attachment-based delivery to breach email defenses.
A security researcher documents a polymorphic phishing page that dynamically changes appearance to evade detection. The attacker's code occasionally malfunctions, causing the phishing page to break. This demonstrates obfuscation techniques used in active phishing campaigns.
NovaCookies, a $320/month AitM phishing toolkit, abuses legitimate DocuSign notifications to redirect Microsoft 365 logins and steal authenticated sessions. The subscription-based platform poses significant risk to organizations by compromising M365 credentials through email-based social engineering attacks.
NovaCookies is a phishing-as-a-service kit enabling attackers to conduct adversary-in-the-middle attacks against Microsoft 365 users, stealing session cookies beyond credentials for $320/month. This lowers the attack complexity for email-based credential harvesting campaigns targeting enterprise cloud environments.
Criminals are using AI voice agents to impersonate Apple Support, targeting stolen-device owners to extract passcodes and 2FA codes via phishing calls. The AnonyMousKIT platform enables bypassing Apple's Activation Lock on stolen devices through a phishing-as-a-service model.
ZeroTokens is a phishing platform enabling attackers to control victim sessions in real time, targeting 53 financial institutions. The tool allows dynamic attack steering, posing a significant threat to enterprise email security and authentication systems.
WhatsApp now supports multiple passkeys per account on iOS and Android, enabling phishing-resistant sign-ins. Over 1 billion users already rely on passkeys. This enhancement strengthens account security against credential-based attacks.
RecruitTrap campaigns are using mobile-optimized phishing pages to impersonate recruiters and steal corporate credentials. The scam targets enterprise employees through mobile devices, attempting to harvest login credentials at scale.
Mirage2FA, a phishing-as-a-service toolkit, compromised 4,500+ US and EU companies by abusing Microsoft 365 login flows to bypass 2FA. The campaign affected 48% of targeted email addresses. This directly impacts email security professionals defending against credential theft and account takeover attacks.
ReliaQuest confirmed that ShinyHunters hackers exploited a phishing-compromised employee account to access a dashboard, though the company states the impact was limited. This incident demonstrates the persistent threat of phishing targeting enterprise security firms.
Researchers discovered iAuthFlow V2, a phishing toolkit that registers attacker-controlled passkeys to maintain persistent access even after victims reset passwords or revoke active sessions. This represents a novel persistence mechanism that bypasses traditional account recovery measures.
Cybercriminals disguise malware as a Google Gemini installer to distribute Vidar stealer, targeting saved browser passwords and credentials. The attack exploits routine software searches rather than email phishing, demonstrating credential-theft risks from trojanized downloads.
Russian cyber-spy groups are conducting targeted phishing campaigns against European and US academics, aerospace, defense, and government officials, abusing OAuth to enhance their attacks. Google has identified three distinct groups running ongoing operations with fewer than 100 targets each.