Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

215 articles
The Hacker News

DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts

DEBULL tooling abuses Microsoft's legitimate device-code flow in a phishing campaign targeting M365 accounts using collaboration-themed lures, exploiting the device login process to compromise victim credentials without fake login pages.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Register

Fake IT bods on Microsoft Teams coax workers into installing malware

Cybercriminals impersonate IT support via Microsoft Teams to trick employees into installing EtherRAT malware. Attacks begin with phishing emails posing as employee surveys, followed by Teams calls requesting remote access. This targets organizations broadly through a multi-stage social engineering campaign.

AI summary · generated with Claude
PhishingHighphishing
Read original
Schneier on Security

Google Is Suing Chinese Scammers Who Are Using Gemini

Google is suing Chinese scammers operating Outsider Enterprise, a phishing-as-a-service operation on Telegram that helps non-technical users create fraudulent websites mimicking Google, YouTube, and government agencies using Gemini AI. This represents Google's enforcement action against organized phishing infrastructure.

AI summary · generated with Claude
PhishingHighphishing
Read original
HackRead

4 Best Email Security Solutions to Keep Employee Inboxes Safe

Article compares four leading email security solutions featuring AI threat detection, phishing defense, malware blocking, and DLP capabilities designed to protect employee inboxes from email-borne threats.

AI summary · generated with Claude
email securityemail security solutionsphishing
Read original
Infosecurity Magazine

Phishing Attacks Targeted Facebook Users With Fake Verification Offer

Phishing attacks targeted Facebook users with fake verification offers and a compromised chatbot to steal sensitive information from business accounts. Attackers impersonated legitimate verification processes to compromise credentials and data.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT

Chinese-linked hackers targeted Indian taxpayers using spear-phishing emails impersonating the Income Tax Department to deliver DcRAT malware. The multi-stage campaign, named Operation DragonReturn, aimed to steal sensitive data from victims' systems via a fake tax filing utility.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

New Avalon Malware Framework Packs CrownX Ransomware Capabilities

Researchers discovered Avalon, a modular malware framework delivered via multi-stage phishing that bundles credential theft, lateral movement, and CrownX ransomware. It bypasses traditional security controls and poses a significant threat to organizations using email as an initial attack vector.

AI summary · generated with Claude
MalwareHighphishing
Read original
Bleeping Computer

ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit

ARToken, a phishing-as-a-service platform affiliated with EvilTokens, was exposed offering a comprehensive Microsoft 365 phishing toolkit. The discovery reveals the scope of commercially available phishing infrastructure targeting enterprise email systems, critical for defenders monitoring active threats.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Register

EvilTokens device-code phishing kit totally more evil than we all thought

EvilTokens device-code phishing kit bypasses MFA and authenticates to Microsoft 365 as victims. Cisco Talos revealed new evasion techniques and capabilities, highlighting the threat's sophistication to email security professionals managing organizational defense.

AI summary · generated with Claude
PhishingHighphishing
Read original
Dark Reading

Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS

Phishing campaigns now auto-adapt payloads based on victim device fingerprinting via user-agent data, delivering OS-specific malware to increase compromise rates and profitability. This technique enhances attacker effectiveness against email targets.

AI summary · generated with Claude
PhishingHighphishing
Read original
Bleeping Computer

Webinar: Why traditional email security is no longer enough

A webinar discussing how modern phishing, BEC, and account takeover attacks bypass traditional email security by exploiting trusted identities and workflows. The presentation covers behavioral AI solutions for automated detection and response.

AI summary · generated with Claude
PhishingphishingBusiness Email Compromiseemail securityemail compromise
Read original
The Hacker News

Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures

Ousaban, a Brazilian banking trojan, targets Iberian bank users via phishing PDFs disguised as corrupted files. The malware verifies victim location in Spain/Portugal before deploying payload hidden in images to steal banking credentials.

AI summary · generated with Claude
PhishingHighphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.