Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

33 articles from Cyber Security News
Cyber Security News

Russian Hackers Target 100+ Organizations With New RedFlick Phishing Attack

Russian state-linked hackers launched RedFlick phishing campaigns targeting 100+ organizations across 13 campaigns (Jan-Aug 2026), using fake professional conversations to replace malicious attachments. Primarily affected US, UK government, diplomacy, research, journalism, and financial sectors. Represents evolved delivery technique with higher evasion potential.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs

Attackers deploy remote access tools disguised as Zoom and PDF installers via phishing emails impersonating meeting invitations and software updates. Victims visiting spoofed download pages unknowingly install backdoors, enabling unauthorized device access. This threatens enterprise security through compromised endpoints.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

RATHat Android Malware Uses Gemini AI to Control Phones Outside Normal App Permissions

RATHat Android malware leverages Gemini AI to control infected phones while evading normal permission restrictions. Distributed via malicious ads and phishing SMS, it exploits Accessibility features to establish persistent command channels targeting users in Europe, Latin America, and Southeast Asia.

AI summary · generated with Claude
MalwareHighphishing
Read original
Cyber Security News

Hackers Use Fake T-Mobile Rewards Expiry Texts to Lure Users to Phishing Sites

Attackers are conducting a widespread SMS phishing campaign impersonating T-Mobile, claiming loyalty points are expiring to trick users into visiting malicious sites that steal login credentials, personal data, and payment information. The campaign began in May 2026 and persists through continuous variations.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

BlackHatSect0r Uses DeepSeek-Powered AI Agent to Automate Attacks and Harvest 16,834 Credentials

BlackHatSect0r used a DeepSeek-powered AI agent to automate credential harvesting and phishing attacks, extracting 16,834 credentials through exposed security gaps. The exposed server revealed phishing tools and a custom DXSCAN platform, demonstrating how AI accelerates credential theft at scale.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

Smishing Hackers Can Watch Every Keystroke as Victims Enter Card Details and OTPs

A smishing campaign intercepts victims' card details and OTPs in real-time through fake payment pages impersonating official services. Attackers use shortened links and urgency tactics to trick users into entering sensitive information that criminals observe live.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks

PAPERMILL campaign uses phishing emails with fake tax-audit notices and Notepad++ signed binaries to deliver VenomRAT malware. Disk-image attachments bypass security email checks (SPF/DKIM/DMARC) and Windows warnings, targeting unsuspecting users with trojan deployment.

AI summary · generated with Claude
PhishingHighDKIMDMARCphishingSPF
Read original
Cyber Security News

Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers

Attackers use Blob URLs and Microsoft Teams to host phishing pages directly in victims' browsers, evading detection. Campaigns begin with DocuSign-themed emails containing malicious calendar invitations that redirect through Microsoft OAuth and Teams endpoints, making the attack appear legitimate while bypassing security inspections.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data

Hackers are using passkey-themed phishing emails and social engineering to compromise Microsoft 365 accounts, bypassing MFA protections. Attackers pose as IT support via calls and texts, directing victims to fake sign-in pages. Compromised accounts facilitate further cloud data theft and Teams-based lure distribution.

AI summary · generated with Claude
PhishingCriticalphishing
Read original
Cyber Security News

Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks

Threat actors leveraged Claude and GPT tools to streamline attacks on government, financial, and transport networks in Latin America. The attacks combined AI-assisted techniques with conventional methods like phishing, malware, and legitimate tool abuse. This demonstrates how commercial AI accelerates existing intrusion workflows rather than introducing fundamentally new attack capabilities.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

Hackers Weaponize ScreenConnect to Spread Worm-Like Malware Across Windows Systems

Attackers are exploiting ScreenConnect remote-access software to distribute worm-like malware across Windows networks via social engineering and phishing. Infected systems can spread payloads to connected machines without requiring individual phishing lures per victim, significantly expanding attack impact.

AI summary · generated with Claude
MalwareHighphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.