Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

229 articles
CyberScoop

Cisco warns customers of actively exploited zero-day in email gateways

Cisco disclosed an actively exploited zero-day in Secure Email Gateway (CVE-2026-76461) allowing remote unauthenticated command execution with root privileges. Attackers have already exploited this critical flaw before patching, potentially compromising email infrastructure and gateway integrity.

AI summary · generated with Claude
VulnerabilityCriticalCVE-2026-76461secure email gateway
Read original
Infosecurity Magazine

Black Axe Members Extradited to US Over Internet Fraud Claims

Black Axe cybercriminal gang members were extradited to the US to face charges related to romance scams, business email compromise (BEC), and money laundering. BEC attacks targeting financial transfers make this directly relevant to email security professionals.

AI summary · generated with Claude
BECHighBEC
Read original
The Hacker News

Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

Cisco Secure Email Gateway has a critical vulnerability (CVE-2026-76461) with a 9.8 CVSS score in AsyncOS email parsing logic. Unauthenticated remote attackers can exploit it for root command execution. Active exploitation in the wild poses immediate risk to email infrastructure.

AI summary · generated with Claude
VulnerabilityCriticalCVE-2026-76461secure email gateway
Read original
The Hacker News

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Threat actors sent over one million phishing emails impersonating CEOs to target Microsoft cloud accounts using passkey-themed social engineering. Attackers exploited third-party email infrastructure to deliver fraud messages and breached cloud environments to exfiltrate data, posing a significant risk to organizations.

AI summary · generated with Claude
PhishingHighphishing
Read original
Dark Reading

Threat Actor Generates 1M Personalized Fraud Emails in 3 Days

A threat actor generated 1 million personalized fraudulent emails in 3 days using AI, enabling attackers to scale phishing/BEC campaigns without sacrificing personalization. This significantly lowers the barrier for effective email-based fraud attacks targeting security defenders and their organizations.

AI summary · generated with Claude
PhishingHighmalicious email
Read original
SecurityWeek

Phishing Research Challenges Conventional Security Awareness Testing

Research analyzing 2.47 million simulated phishing attacks reveals that traditional click-based metrics don't effectively measure security awareness. Organizations should focus on credential compromise and incident reporting instead to better assess real vulnerability to phishing threats.

AI summary · generated with Claude
PhishingMediumphishing
Read original
SecurityWeek

In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

A roundup of cybersecurity news including an InjectEave attack bypassing phishing filters using invisible Unicode, a SIM swapper sentencing, and analysis of Chinese hacking group QTFY's military connections. Invisible Unicode techniques represent an emerging evasion threat for email security systems.

AI summary · generated with Claude
PhishingMediumphishing
Read original
Infosecurity Magazine

Hackers Favor US Eastern Business Hours in M365 Phishing Campaign

KnowBe4 researchers identified a phishing campaign exploiting Microsoft 365's Direct Send feature to deliver malicious emails, with attackers timing submissions during US Eastern business hours to maximize impact and detection evasion.

AI summary · generated with Claude
PhishingHighphishing
Read original
HackRead

Fake Sexual Misconduct Emails Target Universities with Zoho RAT

Phishing emails impersonating sexual misconduct allegations target universities, delivering fake Google Drive links that install Zoho RAT malware. Healthcare-linked institutions are primary targets. This demonstrates email's continued role as the primary attack vector for malware distribution.

AI summary · generated with Claude
PhishingHighphishing
Read original
SecurityWeek

Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

Hackers compromised Brevo marketing platform and sent phishing emails to 347,000 Trezor users plus customers of BitBox and CoinTracking. The attack exploited a third-party service to distribute credential-theft emails targeting cryptocurrency users.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

ThreatsDay roundup covers 200 Android flaws, browser-based phishing techniques, 119K scam shops, and other security incidents. Multiple stories highlight systemic failures where excessive permissions, trusted services exploited for phishing, and unpatched vulnerabilities enable attacks. Relevant to email security professionals monitoring phishing infrastructure and malware delivery mechanisms.

AI summary · generated with Claude
Phishingphishing
Read original
Cyber Security News

Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers

Attackers use Blob URLs and Microsoft Teams to host phishing pages directly in victims' browsers, evading detection. Campaigns begin with DocuSign-themed emails containing malicious calendar invitations that redirect through Microsoft OAuth and Teams endpoints, making the attack appear legitimate while bypassing security inspections.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data

Hackers are using passkey-themed phishing emails and social engineering to compromise Microsoft 365 accounts, bypassing MFA protections. Attackers pose as IT support via calls and texts, directing victims to fake sign-in pages. Compromised accounts facilitate further cloud data theft and Teams-based lure distribution.

AI summary · generated with Claude
PhishingCriticalphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.