Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

215 articles
Infosecurity Magazine

Researchers Spot Uptick in Use of Vercel for Phishing Campaigns

Researchers detected a significant rise in phishing campaigns exploiting Vercel's platform to host malicious content. Attackers leverage Vercel's legitimate hosting service to bypass email security controls and increase campaign credibility. This trend highlights how threat actors abuse trusted infrastructure to improve phishing delivery and evasion.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Microsoft Flags Mass Phishing Campaign Using Fake Compliance Emails

Microsoft detected a large-scale phishing campaign using fake compliance emails to steal credentials from 35,000 users across 13,000 organizations globally. The attack demonstrates how threat actors abuse common organizational compliance processes to deceive targets into surrendering sensitive information.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Fake SSA Emails Drive Venomous#Helper Phishing Campaign

Attackers impersonating the US Social Security Administration send phishing emails containing signed Remote Monitoring and Management software to establish persistent access on American networks. This Venomous#Helper campaign uses credential theft and RMM deployment for ongoing compromise.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

North Korean Hackers Target Crypto Firms with ClickFix and AI-Made Zoom Lures

BlueNoroff, a North Korean hacking group, targeted cryptocurrency firms with spear-phishing campaigns using ClickFix malware and AI-generated Zoom lures. The campaign demonstrates sophisticated social engineering techniques to deliver malware to financial sector targets.

AI summary · generated with Claude
PhishingHighphishing
Read original
The DFIR Report

Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting

An exposed server revealed the Bissa Scanner platform, used for large-scale exploitation and credential harvesting across multiple victims. The operators leveraged AI tools like Claude Code and OpenAI to automate and refine their malicious collection pipeline, demonstrating sophisticated attack infrastructure.

AI summary · generated with Claude
MalwareHighcredential harvesting
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.