Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

215 articles
Cyber Security News

Turkish Banks Targeted by 8,400 Phishing Domains and 6,600 Social Media Scam Ads

Turkish banks face a large-scale fraud campaign using 8,400 phishing domains and 6,600 social media scam ads to steal credentials and money. Attackers impersonate trusted financial brands through fake websites and social ads targeting customers with credential theft and fake loan offers.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Open Directory Exposes Three Evilginx Phishing Operators

A misconfigured open directory exposed infrastructure details for three phishing operators using Evilginx, a tool that bypasses multi-factor authentication. This reveals active phishing campaigns targeting email credentials and MFA tokens, directly impacting email security defenses.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft

Forg365, a phishing-as-a-service platform sold on Telegram for $400/month, targets Microsoft 365 accounts using device code phishing, AitM session theft, and AI-generated lures, followed by mailbox compromise. This threatens organizations relying on Microsoft 365 email and poses significant risk to email security defenders.

AI summary · generated with Claude
PhishingHighphishing
Read original
Dark Reading

Turning the Tables on Email Scammers With 'ScamBuster'

An open-source AI system called 'ScamBuster' uses victim personas to engage phishing attackers, enabling organizations and law enforcement to gather intelligence on criminal operations. This defensive tool helps turn the tables on email scammers by collecting operational data.

AI summary · generated with Claude
Phishingphishing
Read original
The Hacker News

Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365

A misconfigured public web server exposed an active Evilginx phishing operation targeting Microsoft 365, revealing the attacker's toolkit and leading to discovery of two additional related operations. This demonstrates how poor operational security compromises sophisticated phishing infrastructure.

AI summary · generated with Claude
PhishingHighphishing
Read original
SecurityWeek

Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers

Okta reports vishing attacks targeting Microsoft 365 customers, with attackers using phone calls to direct victims to fake Microsoft Entra ID login pages. This phishing technique aims to steal credentials from a widely-used enterprise authentication system.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access

Attackers are using fake Microsoft Entra passkey enrollment prompts via voice-based phishing to compromise Microsoft 365 accounts across multiple sectors. The threat actor O-UNC-066 deploys a panel-controlled phishing kit targeting passkey enrollment, leading to data extortion attacks.

AI summary · generated with Claude
PhishingHighphishing
Read original
ISC SANS

"Comment stuffing" in an HTML phishing attachment as a mechanism for evading AI-based detection?, (Fri, Jul 10th)

Security researchers identified a phishing technique using HTML comment stuffing to evade AI-based email detection systems. This method obscures phishing content within HTML comments, representing an evolving evasion tactic that email security professionals should monitor for detection bypass attempts.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

Hackers Abuse Microsoft Entra Passkey Enrollment to Hijack Enterprise Accounts

Threat group UNC066 has exploited Microsoft Entra passkey enrollment through phone-based phishing since April 2026, tricking employees into registering attacker-controlled passkeys to hijack enterprise accounts. The campaign combines social engineering with custom phishing kits targeting corporate credentials.

AI summary · generated with Claude
PhishingCriticalphishing
Read original
Cyber Security News

UNC6692 Hackers Uses Microsoft Teams Helpdesk Impersonation to Deploy SNOW Malware

UNC6692 threat group uses Microsoft Teams impersonation in spam emails to trick victims into installing SNOW malware. Attackers pose as IT helpdesk staff, exploiting social engineering and trust in familiar tools to gain machine control. This campaign targets organizations via email-based initial contact.

AI summary · generated with Claude
PhishingHighspam
Read original
HackRead

Armored Likho Hits Government, Energy Sectors With BusySnake Stealer

Kaspersky reports that Armored Likho APT group is targeting government and energy sectors using BusySnake Stealer malware, AI-generated loaders, and phishing attacks. This represents an advanced threat combining information-stealing capabilities with sophisticated delivery mechanisms against critical infrastructure.

AI summary · generated with Claude
PhishingHighphishing
Read original
SecurityWeek

Webinar Today: Why Email Security Keeps Failing

A webinar discussing the limitations of email-layer defenses against modern phishing attacks. It addresses why organizations struggle to prevent phishing and suggests need for broader security approaches beyond traditional email filtering.

AI summary · generated with Claude
Phishingemail securityphishing
Read original
The Hacker News

New Ghost Phishing Wave Is Breaking Traditional Email Security

A new 'ghost phishing' technique in the EvilTokens campaign hides malicious pages until decryption in the victim's browser, bypassing traditional email security URL checks. Targets US and Europe businesses seeking Microsoft 365 access and sensitive data.

AI summary · generated with Claude
PhishingHighemail securityphishing
Read original
Dark Reading

Big Brand Jobs Scam Targets Marketing Pros' Google Accounts

A phishing campaign impersonating job opportunities from major brands targets marketing professionals to steal their Google account credentials using nested redirects and evasion techniques.

AI summary · generated with Claude
PhishingHighphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.