Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

229 articles
Cyber Security News

Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks

Threat actors leveraged Claude and GPT tools to streamline attacks on government, financial, and transport networks in Latin America. The attacks combined AI-assisted techniques with conventional methods like phishing, malware, and legitimate tool abuse. This demonstrates how commercial AI accelerates existing intrusion workflows rather than introducing fundamentally new attack capabilities.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cofense

False Allegations, Real Threats: Sexual Misconduct Claims Used as Phishing Lures

Threat actors impersonate university leaders in phishing emails falsely alleging sexual misconduct to trick victims into installing RATs. The social engineering lure exploits sensitive claims to enable malware delivery, providing attackers full system access and control.

AI summary · generated with Claude
PhishingHighphishing
Read original
Dark Reading

Attackers Use Multi-Hop Google Redirects for Phishing Campaign

Attackers are leveraging multi-hop Google redirects to bypass security filters in phishing campaigns designed to steal credentials or deploy ScreenConnect malware. This technique exploits Google's trusted reputation to evade detection systems.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

Autonomous AI agents were used by threat actors to compromise thousands of credentials in under six hours. Google's Threat Intelligence Group observed attackers leveraging a multi-agent framework for large-scale credential harvesting. This represents an escalation in AI-driven attacks that could impact email security defenses.

AI summary · generated with Claude
Highcredential harvesting
Read original
The Register

BigBear phishing crew nets thousands of Microsoft 365 credentials

BigBear phishing crew harvested thousands of Microsoft 365 credentials and session cookies across hundreds of organizations. The operation, using Evilginx2-based phishing-as-a-service, captured hundreds of authenticated sessions capable of bypassing MFA. Researchers gained access to the attackers' admin panel, revealing unprecedented campaign details.

AI summary · generated with Claude
PhishingCriticalphishing
Read original
HackRead

Hackers Stream Real Google Login Pages to Steal Passwords and 2FA Codes

Researchers discovered a phishing service streaming real Google login pages to attackers in real-time, enabling interception of passwords, 2FA codes, and authenticated sessions. This sophisticated credential-theft technique poses significant risk to organizations relying on Google Workspace for email and collaboration.

AI summary · generated with Claude
PhishingHighphishing
Read original
Dark Reading

Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites

Cybercriminals compromised Brazilian government servers to host phishing sites, leveraging a reverse-proxy network with gambling themes. A Chinese-language group is behind the campaign, targeting government and education infrastructure for malicious hosting.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials

CloudSEK discovered BigBear 2.0, a phishing-as-a-service campaign that has stolen over 5000 Microsoft credentials by targeting Microsoft 365 users. This threat directly affects email security as it leverages phishing to compromise email accounts and organizational infrastructure.

AI summary · generated with Claude
PhishingHighphishing
Read original
HackRead

How Hackers Use Email Addresses for Phishing and Account Takeover

Article explains how exposed email addresses facilitate phishing and account takeover attacks, detailing threat mechanisms and defensive practices. Directly addresses email-security risks and protection strategies relevant to security professionals managing email infrastructure and user security.

AI summary · generated with Claude
Phishingphishing
Read original
The Hacker News

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

Attackers are exploiting compromised ScreenConnect clients to distribute a four-stage VBScript malware payload to newly connected systems. Initial compromise vectors include tech-support scams, phishing emails with MSI installers, and fake applications. This affects organizations using ScreenConnect and represents a significant supply-chain-like threat via remote access software.

AI summary · generated with Claude
MalwareHighphishing
Read original
The Hacker News

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

JSCeal, a sophisticated JavaScript malware, can steal session cookies to bypass Google Authentication and conduct surveillance. It features credential harvesting, traffic interception, and multiple obfuscation techniques. This poses significant risk to email users and organizations relying on email-based authentication.

AI summary · generated with Claude
MalwareHighcredential harvesting
Read original
The Register

ASCII smuggling isn't just an AI security risk

Microsoft detected a massive phishing campaign using invisible Unicode characters (ASCII smuggling) to bypass email security filters, peaking at 2.37 million messages. Threat actors adapted AI-era techniques for traditional email phishing attacks. This highlights how obfuscation methods evolve to evade email defenses.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

Microsoft warns of a high-volume phishing campaign exploiting invisible Unicode characters to evade email filters. Attackers split keywords like 'funding' across special characters, bypassing detection while remaining visible to users, directly threatening email security infrastructure.

AI summary · generated with Claude
PhishingHighphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.