Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

229 articles
The Hacker News

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

Phishing campaigns impersonate meeting invitations and software updates to trick users into installing MSP360 RMM software, which attackers then abuse to deploy ScreenConnect for dual-RMM control. This gives threat actors persistent remote access to compromised systems, affecting organizations relying on RMM tools.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

Russian Hackers Target 100+ Organizations With New RedFlick Phishing Attack

Russian state-linked hackers launched RedFlick phishing campaigns targeting 100+ organizations across 13 campaigns (Jan-Aug 2026), using fake professional conversations to replace malicious attachments. Primarily affected US, UK government, diplomacy, research, journalism, and financial sectors. Represents evolved delivery technique with higher evasion potential.

AI summary · generated with Claude
PhishingHighphishing
Read original
HackRead

Global Group Ransomware Abuses WinMerge to Deploy Encryptor

Global Group cybercriminals use payment-themed phishing emails delivering malicious ISO files and legitimate WinMerge tool to deploy ransomware against enterprises. Attackers establish persistence before encryption to facilitate extortion. This phishing-to-ransomware chain targets email security defenses.

AI summary · generated with Claude
PhishingHighphishing
Read original
Dark Reading

Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net

Russia's Star Blizzard APT group has abandoned ClickFix attacks for a new "RedFlick" phishing tactic targeting Ukrainian organizations. The campaign delivers the CosmicPulse backdoor to NGOs, think tanks, and journalists, representing an evolution in their phishing delivery methods and a direct threat to email security defenses.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs

Attackers deploy remote access tools disguised as Zoom and PDF installers via phishing emails impersonating meeting invitations and software updates. Victims visiting spoofed download pages unknowingly install backdoors, enabling unauthorized device access. This threatens enterprise security through compromised endpoints.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

A US-focused phishing campaign targets C-suite executives, stealing Microsoft 365 sessions and deploying remote-access tools (RMM) for persistent compromise. Technology, manufacturing, government, and consulting sectors are heavily affected. This escalates phishing from credential theft to enterprise-wide account takeover.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

RATHat Android Malware Uses Gemini AI to Control Phones Outside Normal App Permissions

RATHat Android malware leverages Gemini AI to control infected phones while evading normal permission restrictions. Distributed via malicious ads and phishing SMS, it exploits Accessibility features to establish persistent command channels targeting users in Europe, Latin America, and Southeast Asia.

AI summary · generated with Claude
MalwareHighphishing
Read original
Cofense

Cofense Vision Extends Post-Perimeter Phishing Defense to Google Workspace

Cofense Vision now integrates with Google Workspace to detect and remove phishing threats that bypass perimeter defenses and reach Gmail inboxes. The solution helps security teams identify and remediate sophisticated phishing attacks post-delivery. This addresses the gap where advanced threats evade traditional email security controls.

AI summary · generated with Claude
Phishingemail securityphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.