Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

121 articles
Cyber Security News

Hackers Can Weaponize Microsoft Copilot to Hijack CEO Accounts and Redirect Wire Transfers

Researchers demonstrated how Microsoft Copilot in Microsoft 365 can be weaponized for business email compromise (BEC) and wire fraud. A single compromised employee account can escalate to CEO takeover and steal $250,000 with minimal attacker effort, posing significant risk to email security.

AI summary · generated with Claude
BECHighBECBusiness Email Compromiseemail compromise
Read original
Cyber Security News

How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways

Phishing remains the primary breach vector, now enhanced by generative AI and account-takeover (AiTM) techniques that bypass email gateways and MFA. Top SOCs are adopting real-time behavioral detonation and threat intelligence to counter dynamic browser-based attacks that traditional email security cannot stop.

AI summary · generated with Claude
PhishingHighphishing
Read original
Dark Reading

Device Code Phishing Up 1,500% in 2026; Vishing Doubles

Device code phishing attacks surged 1,500% in 2026, while vishing (voice phishing) doubled. These social engineering techniques bypass traditional security controls and minimize forensic traces.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cofense

Why Campaign-Level Phishing Defense Is the Future of Email Security

AI-driven phishing campaigns now employ coordinated variations to evade traditional detection. Campaign-level defense strategies are necessary as threat actors generate thousands of unique email variants serving shared objectives, fundamentally changing email security approaches.

AI summary · generated with Claude
PhishingHighemail securitymalicious emailphishing
Read original
ISC SANS

Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)

Phishing campaigns are targeting AI solutions providers by impersonating AI services like ChatGPT. Attackers exploit users' fear of losing access or data to deliver phishing emails. This represents an emerging threat vector leveraging the popularity of AI platforms.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

HollowFrame loader and Matryoshka backdoor were deployed via spear-phishing targeting a law firm. The attack chain began with a phishing email containing a link to an encrypted archive with a malicious LNK file. This undocumented Go and Rust malware represents a sophisticated multi-stage threat.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

Device code phishing exploits OAuth 2.0 device authorization flows to steal access tokens at scale. Originally a red-team technique, it has become a widespread threat affecting various applications beyond input-constrained devices, posing significant risks to credential security and account access.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

AiTM Phishing Becomes Top Initial Access Threat to Law Firms

Adversary-in-the-Middle (AiTM) phishing has become the leading initial access vector for law firms, accounting for 56% of threats. This technique bypasses multi-factor authentication by intercepting credentials in real-time, posing severe risks to organizations handling sensitive client data.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages

Attackers used Teams-themed phishing to abuse Microsoft's legitimate login pages rather than hosting fake ones, making detection harder. Check Point researchers documented this campaign targeting users. This represents an evolution in phishing tactics that security professionals need to identify and defend against.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Register

Russian spies take their half-click email attack from Zimbra to Outlook

Russian espionage group TA488 expanded its half-click phishing attacks from Zimbra to Microsoft Outlook Web Access, exploiting CVE-2026-42897 (XSS flaw in Exchange Server OWA). The attack requires minimal user interaction, posing significant risk to enterprise email environments.

AI summary · generated with Claude
PhishingHighCVE-2026-42897email attack
Read original
Infosecurity Magazine

LogoKit Phishing Kit Screenshots Victim Sites in Real Time

LogoKit phishing kit now generates victim-specific phishing pages using real-time screenshots of target websites, making phishing attacks more convincing and harder to detect. This advancement increases phishing campaign effectiveness against email recipients.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

A Fake Teams Update Can Give Hackers Two Separate Ways to Control Your PC

Operation BlueDash uses phishing emails falsely claiming document-sharing issues to trick users into installing a fake Microsoft Teams update, granting attackers dual remote-control capabilities. The campaign exploits email-based social engineering to deliver malware with multiple persistence mechanisms.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Operation BlueDash uses fake Microsoft Teams update lures to trick users into downloading legitimate RMM tools (Level and ScreenConnect), establishing remote access for potential credential harvesting or system compromise. This phishing campaign targets Teams users via compromised infrastructure and counterfeit Store pages.

AI summary · generated with Claude
PhishingHighphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.