Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

121 articles
Cofense

Click to Sync: From Google Ads Maintenance Notice to Credential Theft

Threat actors are conducting phishing campaigns impersonating Google Ads maintenance notices to steal user credentials. The attacks exploit familiarity and urgency by mimicking legitimate system notifications, targeting Google Ads Sync Account users with fake upgrade alerts.

AI summary · generated with Claude
PhishingHighphishing
Read original
Dark Reading

Attackers Combo Up Evasion Tactics for BEC Phishing

Attackers are combining evasion tactics including fileless techniques and loaders to deploy RATs and stealers in BEC phishing campaigns. This sophisticated approach achieves low detection rates, making it harder for email security systems to catch these threats before they reach users.

AI summary · generated with Claude
BECHighBECphishing
Read original
The Hacker News

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

Researchers at Rapid7 discovered an exposed server containing an AI-assisted phishing toolkit used in active malware campaigns. The toolkit, which includes lure templates and malware builders, was being deployed against Windows users in Mexico via WebDAV to deliver infostealers through spoofed government websites.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Register

AI spam filters are getting suckered by old-school text salting

Attackers are using text salting to evade AI-powered email filters by hiding benign words in phishing emails. Barracuda detected over one million retail-themed phishing attacks using this technique since April, showing that traditional obfuscation methods remain effective against modern defenses.

AI summary · generated with Claude
PhishingHighemail securityphishingspam
Read original
HackRead

“TTF Trap” Phishing Emails Use Fake Font Files to Deliver Windows Malware

Phishing emails with malicious TTF (TrueType Font) files attached are being used to deliver Windows malware. The attack disguises malware as legitimate business documents, exploiting users who trust font files. This represents a novel email-borne malware delivery technique targeting organizations.

AI summary · generated with Claude
PhishingHighphishing
Read original
Dark Reading

1M+ Emails Use Hidden Text to Dupe AI Security Filters

Attackers are using text salting techniques to hide content in over 1 million phishing emails, exploiting weaknesses in AI-based email security filters. This attack method renders AI and large language models ineffective at detecting malicious messages, allowing them to bypass protection systems.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Phishing Campaign Hides Lua Loader as TrueType Font File

A phishing campaign disguises a Lua-based loader as a TrueType font file to distribute remote access trojans and information-stealing malware. The attack uses email-based delivery to compromise targets globally.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps

OkoBot malware framework targets hardware wallet users by injecting phishing prompts into legitimate Ledger and Trezor desktop applications to steal recovery phrases. Active since April 2025, the malware exploits trust in wallet software to compromise cryptocurrency assets on infected Windows systems.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Phishing Campaign Abuses eCards to Deploy RMM Tools

A six-month phishing campaign leveraged seasonal eCard lures to deliver legitimate remote management tools to victims. The attack used social engineering via email to compromise targets. Email security professionals should monitor for eCard-themed phishing and suspicious RMM tool deployments.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Compromised Logins Surge as the Most Common Entry Point for Ransomware Attacks

Sophos research reveals compromised credentials have become the primary ransomware entry point, surpassing software vulnerabilities. Phishing and brute force attacks enable attackers to gain initial access before deploying ransomware, affecting organizations across sectors.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cofense

When Routine Becomes the Threat: The Evolution of Finance-Themed Phishing

Finance-themed phishing campaigns are evolving from urgent, pressure-driven tactics to mundane process-oriented messaging that mimics routine financial workflows. This shift makes phishing emails harder to detect and may indicate broader adoption among threat actors targeting organizations.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

Turkish Banks Targeted by 8,400 Phishing Domains and 6,600 Social Media Scam Ads

Turkish banks face a large-scale fraud campaign using 8,400 phishing domains and 6,600 social media scam ads to steal credentials and money. Attackers impersonate trusted financial brands through fake websites and social ads targeting customers with credential theft and fake loan offers.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Open Directory Exposes Three Evilginx Phishing Operators

A misconfigured open directory exposed infrastructure details for three phishing operators using Evilginx, a tool that bypasses multi-factor authentication. This reveals active phishing campaigns targeting email credentials and MFA tokens, directly impacting email security defenses.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft

Forg365, a phishing-as-a-service platform sold on Telegram for $400/month, targets Microsoft 365 accounts using device code phishing, AitM session theft, and AI-generated lures, followed by mailbox compromise. This threatens organizations relying on Microsoft 365 email and poses significant risk to email security defenders.

AI summary · generated with Claude
PhishingHighphishing
Read original
Dark Reading

Turning the Tables on Email Scammers With 'ScamBuster'

An open-source AI system called 'ScamBuster' uses victim personas to engage phishing attackers, enabling organizations and law enforcement to gather intelligence on criminal operations. This defensive tool helps turn the tables on email scammers by collecting operational data.

AI summary · generated with Claude
Phishingphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.