Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

229 articles
The Hacker News

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

SideCopy, an India-focused threat actor, has expanded targeting to academic institutions via spear-phishing campaigns using ReverseRAT malware. The group leverages mshta.exe abuse to execute malicious scripts and bypass security controls, broadening from government to education sector targets.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cofense

From Payment Plan to Ransomware - Inside a Global Group Attack

A sophisticated ransomware group employs double-extortion tactics globally, infiltrating networks to encrypt data and threaten public disclosure of stolen information. The article examines ransomware attack methods and their impact on critical business systems across industries.

AI summary · generated with Claude
MalwareHighphishing
Read original
Infosecurity Magazine

Revolut Customers Targeted with New Wave of Phishing Attacks

Revolut customers are experiencing a surge in phishing attacks following a recent data breach. Attackers are leveraging stolen customer data to craft convincing phishing messages. This represents a significant risk for email-based credential theft and fraud targeting financial services users.

AI summary · generated with Claude
PhishingHighphishing
Read original
HackRead

Revolut Customers Targeted by Phishing Campaign After Data Breach

Revolut customers face phishing attacks via text messages following a data breach that exposed personal information like IDs and selfies. Attackers are leveraging exposed data to conduct targeted phishing campaigns against financial service users.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

Hackers Use Fake T-Mobile Rewards Expiry Texts to Lure Users to Phishing Sites

Attackers are conducting a widespread SMS phishing campaign impersonating T-Mobile, claiming loyalty points are expiring to trick users into visiting malicious sites that steal login credentials, personal data, and payment information. The campaign began in May 2026 and persists through continuous variations.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

RatHat is a China-based Android malware distributed via smishing and malvertising that uses AI for device control and persists through ADB abuse. It targets mobile devices with SMS phishing and fake app downloads, relevant to email security professionals monitoring phishing campaign vectors.

AI summary · generated with Claude
PhishingHighphishing
Read original
HackRead

Fake OpenAI Billing Emails Target ChatGPT Users in Credential Phishing Scam

Phishing emails impersonating OpenAI billing notices are targeting ChatGPT users to steal credentials and payment details. Cofense researchers discovered the campaign. This directly threatens email users and demonstrates credential harvesting via email deception.

AI summary · generated with Claude
PhishingHighphishing
Read original
HackRead

New GhostCode Phishing Kit Hijacks Microsoft Accounts Despite MFA

Security researchers discovered the GhostCode phishing kit that exploits Microsoft OAuth to bypass MFA protections and steal credentials for Microsoft 365 accounts. The kit uses token-stealing techniques to gain unauthorized access despite multi-factor authentication being enabled, posing a significant threat to enterprise email security.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

BlackHatSect0r Uses DeepSeek-Powered AI Agent to Automate Attacks and Harvest 16,834 Credentials

BlackHatSect0r used a DeepSeek-powered AI agent to automate credential harvesting and phishing attacks, extracting 16,834 credentials through exposed security gaps. The exposed server revealed phishing tools and a custom DXSCAN platform, demonstrating how AI accelerates credential theft at scale.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cofense

Chatbot Conundrum: Phishing Attempts of OpenAI’s ChatGPT

Threat actors are leveraging ChatGPT's subscription model to conduct phishing attacks, sending fake payment update notifications to users. These familiar billing lures target ChatGPT's large user base to steal credentials and sensitive information.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

Smishing Hackers Can Watch Every Keystroke as Victims Enter Card Details and OTPs

A smishing campaign intercepts victims' card details and OTPs in real-time through fake payment pages impersonating official services. Attackers use shortened links and urgency tactics to trick users into entering sensitive information that criminals observe live.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks

PAPERMILL campaign uses phishing emails with fake tax-audit notices and Notepad++ signed binaries to deliver VenomRAT malware. Disk-image attachments bypass security email checks (SPF/DKIM/DMARC) and Windows warnings, targeting unsuspecting users with trojan deployment.

AI summary · generated with Claude
PhishingHighDKIMDMARCphishingSPF
Read original
The Hacker News

N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security

N0va phishkit targets US and EU businesses with sophisticated phishing campaigns impersonating trusted services to compromise legitimate accounts. Attackers bypass malware detection by leveraging valid credentials to access sensitive data and business systems, posing significant risk to organizations.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Register

Cisco email security boxes can be rooted by... an email

Cisco Secure Email Gateway contains a critical flaw (CVE-2026-76461) allowing attackers to gain root access via malicious email. The 9.8 CVSS vulnerability affects all appliances with no workarounds, requiring immediate patching. Email security professionals must prioritize updates to prevent full system compromise.

AI summary · generated with Claude
VulnerabilityCriticalCVE-2026-76461email securitymalicious emailsecure email gateway
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.