Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

33 articles from Cyber Security News
Cyber Security News

Hackers Use QR Codes in Phishing Emails to Steal Login Credentials

Hackers are using QR codes in phishing emails ("quishing") to steal login credentials by hiding malicious URLs in QR codes that appear less suspicious than text links. This tactic exploited people's trust in QR codes as routine shortcuts and reached record levels in H1 2026.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

Hackers Hide Agent Tesla JScript Behind Unicode Emojis to Evade Detection

Hackers hide Agent Tesla JScript malware behind Unicode emojis in BEC emails targeting finance teams. The obfuscated script mimics legitimate banking documents to evade detection and trick recipients into executing malware.

AI summary · generated with Claude
BECHighBusiness Email Compromiseemail compromise
Read original
Cyber Security News

Hackers Use Fake Google Gemini Installer to Deploy Vidar Stealer and Steal Browser Credentials

Cybercriminals disguise malware as a Google Gemini installer to distribute Vidar stealer, targeting saved browser passwords and credentials. The attack exploits routine software searches rather than email phishing, demonstrating credential-theft risks from trojanized downloads.

AI summary · generated with Claude
MalwareHighphishing
Read original
Cyber Security News

Hackers Let Microsoft 365 Users Complete MFA, Then Steal Logged-In Sessions

Mirage2FA, a Phishing-as-a-Service platform, enables attackers to bypass Microsoft 365 MFA by allowing users to complete normal login, then stealing authenticated sessions via an adversary-in-the-middle attack. Thousands of compromise events have occurred since late 2024.

AI summary · generated with Claude
PhishingCriticalphishing
Read original
Cyber Security News

Hackers Use AI Voice Calls and Fake Banking Pages to Bypass MFA and Steal Accounts

Hackers use AI-generated voice calls paired with fake banking pages to bypass MFA and steal credentials from Mexican financial institutions. The Balonx Sistema campaign targets 20+ banks and has compromised 1,100+ accounts since October 2025 by requesting sensitive information during live phishing sessions.

AI summary · generated with Claude
PhishingCriticalphishing
Read original
Cyber Security News

Microsoft to Make Passkeys Default in Entra ID and Retires SMS and Voice Authentication

Microsoft is making passkeys the default authentication method in Entra ID and retiring SMS/voice authentication by September 2026, shifting toward phishing-resistant credentials. This impacts organizations relying on traditional MFA methods and requires migration planning to passkey-based authentication.

AI summary · generated with Claude
Standards & policyphishing
Read original
Cyber Security News

7-Zip Mark-of-the-Web Bypass Lets Malicious Files Evade Windows SmartScreen

A 7-Zip vulnerability allows attackers to bypass Windows SmartScreen warnings by removing the Mark-of-the-Web indicator from extracted files. This is particularly dangerous in phishing campaigns where archives disguised as invoices or documents trick users into extraction, enabling malware execution without security prompts.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

Hackers Can Weaponize Microsoft Copilot to Hijack CEO Accounts and Redirect Wire Transfers

Researchers demonstrated how Microsoft Copilot in Microsoft 365 can be weaponized for business email compromise (BEC) and wire fraud. A single compromised employee account can escalate to CEO takeover and steal $250,000 with minimal attacker effort, posing significant risk to email security.

AI summary · generated with Claude
BECHighBECBusiness Email Compromiseemail compromise
Read original
Cyber Security News

How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways

Phishing remains the primary breach vector, now enhanced by generative AI and account-takeover (AiTM) techniques that bypass email gateways and MFA. Top SOCs are adopting real-time behavioral detonation and threat intelligence to counter dynamic browser-based attacks that traditional email security cannot stop.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

A Fake Teams Update Can Give Hackers Two Separate Ways to Control Your PC

Operation BlueDash uses phishing emails falsely claiming document-sharing issues to trick users into installing a fake Microsoft Teams update, granting attackers dual remote-control capabilities. The campaign exploits email-based social engineering to deliver malware with multiple persistence mechanisms.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

Hackers Hijack 20+ Government Websites to Deliver Malware Through Trusted Links

PhantomEnigma campaign hijacks 20+ Brazilian government websites to distribute malware via trusted domains. Attackers compromised government mailboxes to send authenticated phishing emails bypassing SPF/DKIM/DMARC checks, targeting banking and public-sector organizations.

AI summary · generated with Claude
PhishingCriticalDKIMDMARCphishingSPF
Read original
Cyber Security News

One Security Alert Exposed a GenAI-Powered Malware Factory Containing More Than 1,000 Attack Files

A misconfigured WebDAV server exposed a malware factory containing over 1,000 attack files, including phishing lures, droppers, and malware variants. The GenAI-powered operation targeted Windows users with fake documents and malicious shortcuts. The discovery reveals detailed insights into attacker infrastructure and malware development practices.

AI summary · generated with Claude
MalwareHighphishing
Read original
Cyber Security News

Turkish Banks Targeted by 8,400 Phishing Domains and 6,600 Social Media Scam Ads

Turkish banks face a large-scale fraud campaign using 8,400 phishing domains and 6,600 social media scam ads to steal credentials and money. Attackers impersonate trusted financial brands through fake websites and social ads targeting customers with credential theft and fake loan offers.

AI summary · generated with Claude
PhishingHighphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.