Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

121 articles
Infosecurity Magazine

Phishing Attacks Targeted Facebook Users With Fake Verification Offer

Phishing attacks targeted Facebook users with fake verification offers and a compromised chatbot to steal sensitive information from business accounts. Attackers impersonated legitimate verification processes to compromise credentials and data.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT

Chinese-linked hackers targeted Indian taxpayers using spear-phishing emails impersonating the Income Tax Department to deliver DcRAT malware. The multi-stage campaign, named Operation DragonReturn, aimed to steal sensitive data from victims' systems via a fake tax filing utility.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

New Avalon Malware Framework Packs CrownX Ransomware Capabilities

Researchers discovered Avalon, a modular malware framework delivered via multi-stage phishing that bundles credential theft, lateral movement, and CrownX ransomware. It bypasses traditional security controls and poses a significant threat to organizations using email as an initial attack vector.

AI summary · generated with Claude
MalwareHighphishing
Read original
Bleeping Computer

ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit

ARToken, a phishing-as-a-service platform affiliated with EvilTokens, was exposed offering a comprehensive Microsoft 365 phishing toolkit. The discovery reveals the scope of commercially available phishing infrastructure targeting enterprise email systems, critical for defenders monitoring active threats.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Register

EvilTokens device-code phishing kit totally more evil than we all thought

EvilTokens device-code phishing kit bypasses MFA and authenticates to Microsoft 365 as victims. Cisco Talos revealed new evasion techniques and capabilities, highlighting the threat's sophistication to email security professionals managing organizational defense.

AI summary · generated with Claude
PhishingHighphishing
Read original
Dark Reading

Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS

Phishing campaigns now auto-adapt payloads based on victim device fingerprinting via user-agent data, delivering OS-specific malware to increase compromise rates and profitability. This technique enhances attacker effectiveness against email targets.

AI summary · generated with Claude
PhishingHighphishing
Read original
Bleeping Computer

Webinar: Why traditional email security is no longer enough

A webinar discussing how modern phishing, BEC, and account takeover attacks bypass traditional email security by exploiting trusted identities and workflows. The presentation covers behavioral AI solutions for automated detection and response.

AI summary · generated with Claude
PhishingphishingBusiness Email Compromiseemail securityemail compromise
Read original
The Hacker News

Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures

Ousaban, a Brazilian banking trojan, targets Iberian bank users via phishing PDFs disguised as corrupted files. The malware verifies victim location in Spain/Portugal before deploying payload hidden in images to steal banking credentials.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Brazilian Banking Trojan Ousaban Targets Spain and Portugal

Brazilian banking trojan Ousaban is actively targeting Spain and Portugal through phishing campaigns. FortiGuard has identified the threat, which uses email as a delivery vector to compromise financial accounts in the region.

AI summary · generated with Claude
PhishingHighphishing
Read original
CyberScoop

This phishing kit looks more like BEC-as-a-service

Researchers discovered ARToken, a business email compromise-as-a-service platform affiliated with EvilTokens phishing operation. The toolkit is designed to bypass MFA and compromise Microsoft 365 accounts, representing an advanced threat targeting organizations.

AI summary · generated with Claude
BECHighphishingBECBusiness Email Compromiseemail compromise
Read original
The Hacker News

Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware

Attackers are registering fake domains that LLMs hallucinate and suggest to users, then hosting phishing pages to capture traffic. This "phantom squatting" technique exploits AI's tendency to invent non-existent URLs, creating new phishing vectors that email users may encounter.

AI summary · generated with Claude
PhishingHighphishing
Read original
ISC SANS

Why Ask Credentials If There Are Secret Codes?, (Wed, Jul 1st)

A phishing campaign targeting MetaMask cryptocurrency wallet users was detected. The attack uses alternative authentication methods instead of traditional credential theft, demonstrating evolving phishing tactics that security professionals should recognize.

AI summary · generated with Claude
PhishingMediumphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.