Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

49 articles from The Hacker News
The Hacker News

US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries

A phishing campaign using Canadian tax forms has expanded to 46 countries, with 45% of attacks targeting the US. The campaign delivers Remote Monitoring and Management (RMM) malware via deceptive tax documents, representing a significant threat to organizations globally.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

NovaCookies, a $320/month AitM phishing toolkit, abuses legitimate DocuSign notifications to redirect Microsoft 365 logins and steal authenticated sessions. The subscription-based platform poses significant risk to organizations by compromising M365 credentials through email-based social engineering attacks.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

Criminals are using AI voice agents to impersonate Apple Support, targeting stolen-device owners to extract passcodes and 2FA codes via phishing calls. The AnonyMousKIT platform enables bypassing Apple's Activation Lock on stolen devices through a phishing-as-a-service model.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

Mirage2FA, a phishing-as-a-service toolkit, compromised 4,500+ US and EU companies by abusing Microsoft 365 login flows to bypass 2FA. The campaign affected 48% of targeted email addresses. This directly impacts email security professionals defending against credential theft and account takeover attacks.

AI summary · generated with Claude
PhishingCriticalphishing
Read original
The Hacker News

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

Attackers exploited 24 npm packages to host fake Cloudflare CAPTCHA pages for phishing attacks. The malicious packages leverage unpkg mirrors as free infrastructure to redirect users to ClickFix-style scam pages. This highlights supply chain risks where legitimate package repositories enable phishing campaigns.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Phishing 3.0: The Fight Moves to Agent Versus Agent

Phishing tactics have evolved beyond payload-based detection toward AI-driven attacks where intent matters more than content. Traditional email defenses struggle as attackers increasingly use AI agents, requiring defenders to adopt new strategies.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps

CTM360 discovered over 3,000 recruitment phishing URLs using Browser-in-the-Browser technique to steal Google and Facebook credentials and intercept MFA prompts. The global campaign targets job seekers with fake interview pages. This represents a significant phishing threat exploiting social engineering and advanced credential-theft tactics.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

Researchers discovered three attack methods bypassing passkey protections: exploiting Windows authentication material exposure, abusing cloud-synced passkeys via malware, and using phishing-resistant MFA workarounds. Passkeys are increasingly used for email account protection, making these attacks directly relevant to email security practitioners.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

UNC6671, a data extortion group, conducts vishing attacks on personal phones impersonating IT staff to trick enterprise employees into compromising SaaS credentials. The campaign targets financial services, private equity, and professional services sectors, bypassing traditional email security controls.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

Greatness PhaaS now supports device code phishing to bypass MFA and steal OAuth tokens. This technique abuses legitimate OAuth 2.0 Device Authorization Grant flows. Critical threat for organizations as attackers can compromise accounts despite MFA protections.

AI summary · generated with Claude
PhishingCriticalphishing
Read original
The Hacker News

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

HollowFrame loader and Matryoshka backdoor were deployed via spear-phishing targeting a law firm. The attack chain began with a phishing email containing a link to an encrypted archive with a malicious LNK file. This undocumented Go and Rust malware represents a sophisticated multi-stage threat.

AI summary · generated with Claude
PhishingHighphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.