Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

This week in email security

AI briefing · 2026-09-27

AI-powered phishing escalates while Microsoft dismantles EvilTokens infrastructure

215 articles
Infosecurity Magazine

Researchers Identify AliExpress Phishing Domains Before Registration

Security researchers at EfficientIP identified phishing domains impersonating AliExpress before registration completion, demonstrating proactive threat detection capabilities. This highlights the vulnerability of popular e-commerce brands to phishing attacks and the importance of domain monitoring for email security.

AI summary · generated with Claude
PhishingMediumphishing
Read original
Dark Reading

'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing

Researchers discovered 'Salesbleed,' an attack that exploits Salesforce Agents to inject malicious instructions into Slack, enabling phishing attacks through trusted internal communication channels. This demonstrates how agentic AI systems can be manipulated to deliver harmful payloads across integrated business applications, posing risks to enterprise messaging security.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Register

Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing

Salesforce Agentforce contained three critical vulnerabilities allowing attackers to hijack AI agents, steal CRM data without user interaction, and send phishing messages. Zenity Labs discovered the flaws and Salesforce has patched them, but the incident highlights risks in AI-driven business applications.

AI summary · generated with Claude
PhishingHighphishing
Read original
ISC SANS

One URL, Three Different Tricks, (Thu, Sep 24th)

A phishing email uses a specially crafted URL designed to bypass security controls through obfuscation techniques. The URL structure employs multiple tricks to evade detection while appearing as garbage to basic defenses. Email security professionals should understand these evasion tactics.

AI summary · generated with Claude
PhishingMediumphishing
Read original
Dark Reading

Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign

Attackers are poisoning AI chatbots by seeding the web with malicious links and data, which are then displayed in ChatGPT, Gemini, and Google AI responses. This technique facilitates mass disinformation and phishing campaigns targeting users who trust AI-generated answers.

AI summary · generated with Claude
PhishingHighphishing
Read original
SecurityWeek

AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft

Microsoft disrupted EvilTokens, an AI-powered phishing platform that automated social engineering attacks and target selection. The platform represented an escalated threat using machine learning across the entire attack chain, now taken offline by Microsoft's intervention.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cofense

Cofense Expands AI-Driven Phishing Defense Platform to Advance Secure Behavior Management

Cofense launched a new Competency Dashboard within its Command Center platform to measure organizational readiness against phishing threats and track employee behavior in recognizing and reporting phishing attempts. This AI-driven enhancement aims to consolidate phishing defense visibility and employee response metrics into a unified view.

AI summary · generated with Claude
Phishingphishing
Read original
Dark Reading

Microsoft Disrupts EvilTokens Device Code Phishing Service

Microsoft disrupted EvilTokens, a phishing-as-a-service platform targeting Microsoft 365 accounts, by seizing 50 websites and disabling 150+ domains. The action targets automated credential theft attacks leveraging device code authentication flows. This matters to security professionals managing email and cloud identity threats.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

Microsoft disabled EvilTokens, an AI-powered device-code phishing service responsible for compromising approximately 12,000 inboxes. The takedown was coordinated with law enforcement and multiple tech companies. This represents a significant disruption to a major phishing-as-a-service operation targeting email accounts.

AI summary · generated with Claude
PhishingHighphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.