Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

28 articles from Infosecurity Magazine in Phishing
Infosecurity Magazine

Fake Bank of America Phishing Scam Installs Remote Access Malware

Cybercriminals are running a phishing campaign impersonating Bank of America to distribute malware that installs ScreenConnect remote access tools. The scam enables attackers to gain persistent system access and control compromised machines.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

AiTM Phishing Becomes Top Initial Access Threat to Law Firms

Adversary-in-the-Middle (AiTM) phishing has become the leading initial access vector for law firms, accounting for 56% of threats. This technique bypasses multi-factor authentication by intercepting credentials in real-time, posing severe risks to organizations handling sensitive client data.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages

Attackers used Teams-themed phishing to abuse Microsoft's legitimate login pages rather than hosting fake ones, making detection harder. Check Point researchers documented this campaign targeting users. This represents an evolution in phishing tactics that security professionals need to identify and defend against.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

LogoKit Phishing Kit Screenshots Victim Sites in Real Time

LogoKit phishing kit now generates victim-specific phishing pages using real-time screenshots of target websites, making phishing attacks more convincing and harder to detect. This advancement increases phishing campaign effectiveness against email recipients.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

ChatGPT Among Top 10 Most Impersonated Brands in Phishing Attacks, Says Check Point

ChatGPT entered the top 10 most impersonated brands in phishing attacks according to Check Point research. Attackers are leveraging the brand's popularity to deceive users. This represents a growing threat vector email security professionals must monitor and defend against.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Phishing Campaign Hides Lua Loader as TrueType Font File

A phishing campaign disguises a Lua-based loader as a TrueType font file to distribute remote access trojans and information-stealing malware. The attack uses email-based delivery to compromise targets globally.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Phishing Campaign Abuses eCards to Deploy RMM Tools

A six-month phishing campaign leveraged seasonal eCard lures to deliver legitimate remote management tools to victims. The attack used social engineering via email to compromise targets. Email security professionals should monitor for eCard-themed phishing and suspicious RMM tool deployments.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Compromised Logins Surge as the Most Common Entry Point for Ransomware Attacks

Sophos research reveals compromised credentials have become the primary ransomware entry point, surpassing software vulnerabilities. Phishing and brute force attacks enable attackers to gain initial access before deploying ransomware, affecting organizations across sectors.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Open Directory Exposes Three Evilginx Phishing Operators

A misconfigured open directory exposed infrastructure details for three phishing operators using Evilginx, a tool that bypasses multi-factor authentication. This reveals active phishing campaigns targeting email credentials and MFA tokens, directly impacting email security defenses.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Phishing Attacks Targeted Facebook Users With Fake Verification Offer

Phishing attacks targeted Facebook users with fake verification offers and a compromised chatbot to steal sensitive information from business accounts. Attackers impersonated legitimate verification processes to compromise credentials and data.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Brazilian Banking Trojan Ousaban Targets Spain and Portugal

Brazilian banking trojan Ousaban is actively targeting Spain and Portugal through phishing campaigns. FortiGuard has identified the threat, which uses email as a delivery vector to compromise financial accounts in the region.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Hackers Leverage Blockchain to Hit Japan's Hotels Through Booking.com Phishing

Hackers sent phishing emails to Japanese hotels partnered with Booking.com in May, distributing malware hosted on blockchain networks. The campaign targeted accommodation partners through credential-stealing phishing, enabling unauthorized access to booking accounts and guest data.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

FBI Sounds Alarm Over Russian Intelligence Signal Phishing

The FBI warns that Russian intelligence actors are conducting phishing campaigns to steal Signal backup encryption keys. This targets users' end-to-end encrypted communications. Email security professionals should monitor for phishing emails luring users to compromise their encrypted messaging credentials.

AI summary · generated with Claude
PhishingHighphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.