Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

107 articles in Phishing
HackRead

Armored Likho Hits Government, Energy Sectors With BusySnake Stealer

Kaspersky reports that Armored Likho APT group is targeting government and energy sectors using BusySnake Stealer malware, AI-generated loaders, and phishing attacks. This represents an advanced threat combining information-stealing capabilities with sophisticated delivery mechanisms against critical infrastructure.

AI summary · generated with Claude
PhishingHighphishing
Read original
SecurityWeek

Webinar Today: Why Email Security Keeps Failing

A webinar discussing the limitations of email-layer defenses against modern phishing attacks. It addresses why organizations struggle to prevent phishing and suggests need for broader security approaches beyond traditional email filtering.

AI summary · generated with Claude
Phishingemail securityphishing
Read original
The Hacker News

New Ghost Phishing Wave Is Breaking Traditional Email Security

A new 'ghost phishing' technique in the EvilTokens campaign hides malicious pages until decryption in the victim's browser, bypassing traditional email security URL checks. Targets US and Europe businesses seeking Microsoft 365 access and sensitive data.

AI summary · generated with Claude
PhishingHighemail securityphishing
Read original
Dark Reading

Big Brand Jobs Scam Targets Marketing Pros' Google Accounts

A phishing campaign impersonating job opportunities from major brands targets marketing professionals to steal their Google account credentials using nested redirects and evasion techniques.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts

DEBULL tooling abuses Microsoft's legitimate device-code flow in a phishing campaign targeting M365 accounts using collaboration-themed lures, exploiting the device login process to compromise victim credentials without fake login pages.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Register

Fake IT bods on Microsoft Teams coax workers into installing malware

Cybercriminals impersonate IT support via Microsoft Teams to trick employees into installing EtherRAT malware. Attacks begin with phishing emails posing as employee surveys, followed by Teams calls requesting remote access. This targets organizations broadly through a multi-stage social engineering campaign.

AI summary · generated with Claude
PhishingHighphishing
Read original
Schneier on Security

Google Is Suing Chinese Scammers Who Are Using Gemini

Google is suing Chinese scammers operating Outsider Enterprise, a phishing-as-a-service operation on Telegram that helps non-technical users create fraudulent websites mimicking Google, YouTube, and government agencies using Gemini AI. This represents Google's enforcement action against organized phishing infrastructure.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Phishing Attacks Targeted Facebook Users With Fake Verification Offer

Phishing attacks targeted Facebook users with fake verification offers and a compromised chatbot to steal sensitive information from business accounts. Attackers impersonated legitimate verification processes to compromise credentials and data.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT

Chinese-linked hackers targeted Indian taxpayers using spear-phishing emails impersonating the Income Tax Department to deliver DcRAT malware. The multi-stage campaign, named Operation DragonReturn, aimed to steal sensitive data from victims' systems via a fake tax filing utility.

AI summary · generated with Claude
PhishingHighphishing
Read original
Bleeping Computer

ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit

ARToken, a phishing-as-a-service platform affiliated with EvilTokens, was exposed offering a comprehensive Microsoft 365 phishing toolkit. The discovery reveals the scope of commercially available phishing infrastructure targeting enterprise email systems, critical for defenders monitoring active threats.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Register

EvilTokens device-code phishing kit totally more evil than we all thought

EvilTokens device-code phishing kit bypasses MFA and authenticates to Microsoft 365 as victims. Cisco Talos revealed new evasion techniques and capabilities, highlighting the threat's sophistication to email security professionals managing organizational defense.

AI summary · generated with Claude
PhishingHighphishing
Read original
Dark Reading

Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS

Phishing campaigns now auto-adapt payloads based on victim device fingerprinting via user-agent data, delivering OS-specific malware to increase compromise rates and profitability. This technique enhances attacker effectiveness against email targets.

AI summary · generated with Claude
PhishingHighphishing
Read original
Bleeping Computer

Webinar: Why traditional email security is no longer enough

A webinar discussing how modern phishing, BEC, and account takeover attacks bypass traditional email security by exploiting trusted identities and workflows. The presentation covers behavioral AI solutions for automated detection and response.

AI summary · generated with Claude
PhishingphishingBusiness Email Compromiseemail securityemail compromise
Read original
The Hacker News

Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures

Ousaban, a Brazilian banking trojan, targets Iberian bank users via phishing PDFs disguised as corrupted files. The malware verifies victim location in Spain/Portugal before deploying payload hidden in images to steal banking credentials.

AI summary · generated with Claude
PhishingHighphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.