Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

229 articles
The Hacker News

ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

ThreatsDay roundup covers multiple attack vectors including CEO phishing kits, compromised Dropbox accounts, and OAuth-based attacks. Attackers leverage legitimate-looking communications and trusted platforms to gain access, exploiting human trust rather than technical vulnerabilities.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

Hackers Weaponize ScreenConnect to Spread Worm-Like Malware Across Windows Systems

Attackers are exploiting ScreenConnect remote-access software to distribute worm-like malware across Windows networks via social engineering and phishing. Infected systems can spread payloads to connected machines without requiring individual phishing lures per victim, significantly expanding attack impact.

AI summary · generated with Claude
MalwareHighphishing
Read original
Cyber Security News

Hackers Use QR Codes in Phishing Emails to Steal Login Credentials

Hackers are using QR codes in phishing emails ("quishing") to steal login credentials by hiding malicious URLs in QR codes that appear less suspicious than text links. This tactic exploited people's trust in QR codes as routine shortcuts and reached record levels in H1 2026.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Outsider Phishing Kit Survives Takedown With 700 New Pages

A phishing kit called Outsider generated 700 new pages after Google led a takedown effort, demonstrating the threat actor's resilience and ability to quickly recreate malicious infrastructure.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries

A phishing campaign using Canadian tax forms has expanded to 46 countries, with 45% of attacks targeting the US. The campaign delivers Remote Monitoring and Management (RMM) malware via deceptive tax documents, representing a significant threat to organizations globally.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Register

Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes

Law enforcement and CrowdStrike disrupted the 23-year-old Sality peer-to-peer botnet affecting 15,000+ machines worldwide. The botnet distributed malware enabling credential theft, spam, proxying, and DDoS attacks. This takedown protects organizations from ongoing malware delivery and credential compromise risks.

AI summary · generated with Claude
MalwareHighspam
Read original
CyberScoop

FBI raises alarm over deceptive phishing campaign targeting prominent people

FBI warns of phishing campaign targeting high-profile individuals and their contacts via commercial messaging apps. Attackers impersonate government officials and journalists to gain account access and steal sensitive data. The campaign demonstrates evolving social engineering tactics against prominent figures.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cofense

Why Cofense AI Is Different: Built for the Reality That Phishing Gets Through

Cofense discusses its AI-powered phishing defense approach, emphasizing that effective anti-phishing solutions must handle threats that bypass initial defenses. The article addresses security leaders' focus on AI effectiveness rather than mere presence in phishing defense strategies.

AI summary · generated with Claude
Phishingphishing
Read original
Infosecurity Magazine

Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign

A large-scale phishing campaign used SVG attachments disguised as voicemail notifications to evade email security controls. The attack targeted 5527 organizations with 26,000+ malicious messages, exploiting attachment-based delivery to breach email defenses.

AI summary · generated with Claude
PhishingHighphishing
Read original
ISC SANS

A polymorphic phishing page (that occasionally breaks itself), (Thu, Aug 27th)

A security researcher documents a polymorphic phishing page that dynamically changes appearance to evade detection. The attacker's code occasionally malfunctions, causing the phishing page to break. This demonstrates obfuscation techniques used in active phishing campaigns.

AI summary · generated with Claude
PhishingMediumphishingspam
Read original
The Hacker News

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

NovaCookies, a $320/month AitM phishing toolkit, abuses legitimate DocuSign notifications to redirect Microsoft 365 logins and steal authenticated sessions. The subscription-based platform poses significant risk to organizations by compromising M365 credentials through email-based social engineering attacks.

AI summary · generated with Claude
PhishingHighphishing
Read original
Dark Reading

'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month

NovaCookies is a phishing-as-a-service kit enabling attackers to conduct adversary-in-the-middle attacks against Microsoft 365 users, stealing session cookies beyond credentials for $320/month. This lowers the attack complexity for email-based credential harvesting campaigns targeting enterprise cloud environments.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

Criminals are using AI voice agents to impersonate Apple Support, targeting stolen-device owners to extract passcodes and 2FA codes via phishing calls. The AnonyMousKIT platform enables bypassing Apple's Activation Lock on stolen devices through a phishing-as-a-service model.

AI summary · generated with Claude
PhishingHighphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.