Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

26 articles from The Hacker News
The Hacker News

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps

OkoBot malware framework targets hardware wallet users by injecting phishing prompts into legitimate Ledger and Trezor desktop applications to steal recovery phrases. Active since April 2025, the malware exploits trust in wallet software to compromise cryptocurrency assets on infected Windows systems.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft

Forg365, a phishing-as-a-service platform sold on Telegram for $400/month, targets Microsoft 365 accounts using device code phishing, AitM session theft, and AI-generated lures, followed by mailbox compromise. This threatens organizations relying on Microsoft 365 email and poses significant risk to email security defenders.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365

A misconfigured public web server exposed an active Evilginx phishing operation targeting Microsoft 365, revealing the attacker's toolkit and leading to discovery of two additional related operations. This demonstrates how poor operational security compromises sophisticated phishing infrastructure.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access

Attackers are using fake Microsoft Entra passkey enrollment prompts via voice-based phishing to compromise Microsoft 365 accounts across multiple sectors. The threat actor O-UNC-066 deploys a panel-controlled phishing kit targeting passkey enrollment, leading to data extortion attacks.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

New Ghost Phishing Wave Is Breaking Traditional Email Security

A new 'ghost phishing' technique in the EvilTokens campaign hides malicious pages until decryption in the victim's browser, bypassing traditional email security URL checks. Targets US and Europe businesses seeking Microsoft 365 access and sensitive data.

AI summary · generated with Claude
PhishingHighemail securityphishing
Read original
The Hacker News

DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts

DEBULL tooling abuses Microsoft's legitimate device-code flow in a phishing campaign targeting M365 accounts using collaboration-themed lures, exploiting the device login process to compromise victim credentials without fake login pages.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT

Chinese-linked hackers targeted Indian taxpayers using spear-phishing emails impersonating the Income Tax Department to deliver DcRAT malware. The multi-stage campaign, named Operation DragonReturn, aimed to steal sensitive data from victims' systems via a fake tax filing utility.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

New Avalon Malware Framework Packs CrownX Ransomware Capabilities

Researchers discovered Avalon, a modular malware framework delivered via multi-stage phishing that bundles credential theft, lateral movement, and CrownX ransomware. It bypasses traditional security controls and poses a significant threat to organizations using email as an initial attack vector.

AI summary · generated with Claude
MalwareHighphishing
Read original
The Hacker News

Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures

Ousaban, a Brazilian banking trojan, targets Iberian bank users via phishing PDFs disguised as corrupted files. The malware verifies victim location in Spain/Portugal before deploying payload hidden in images to steal banking credentials.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware

Attackers are registering fake domains that LLMs hallucinate and suggest to users, then hosting phishing pages to capture traffic. This "phantom squatting" technique exploits AI's tendency to invent non-existent URLs, creating new phishing vectors that email users may encounter.

AI summary · generated with Claude
PhishingHighphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.