Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

229 articles
Infosecurity Magazine

ZeroTokens Phishing Platform Steers Attacks in Real Time

ZeroTokens is a phishing platform enabling attackers to control victim sessions in real time, targeting 53 financial institutions. The tool allows dynamic attack steering, posing a significant threat to enterprise email security and authentication systems.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Fake Recruiter Scams Target Corporate Credentials on Mobile

RecruitTrap campaigns are using mobile-optimized phishing pages to impersonate recruiters and steal corporate credentials. The scam targets enterprise employees through mobile devices, attempting to harvest login credentials at scale.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

Mirage2FA, a phishing-as-a-service toolkit, compromised 4,500+ US and EU companies by abusing Microsoft 365 login flows to bypass 2FA. The campaign affected 48% of targeted email addresses. This directly impacts email security professionals defending against credential theft and account takeover attacks.

AI summary · generated with Claude
PhishingCriticalphishing
Read original
The Hacker News

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

Attackers exploited 24 npm packages to host fake Cloudflare CAPTCHA pages for phishing attacks. The malicious packages leverage unpkg mirrors as free infrastructure to redirect users to ClickFix-style scam pages. This highlights supply chain risks where legitimate package repositories enable phishing campaigns.

AI summary · generated with Claude
PhishingHighphishing
Read original
SecurityWeek

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

ReliaQuest confirmed that ShinyHunters hackers exploited a phishing-compromised employee account to access a dashboard, though the company states the impact was limited. This incident demonstrates the persistent threat of phishing targeting enterprise security firms.

AI summary · generated with Claude
PhishingMediumphishing
Read original
SecurityWeek

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

Researchers discovered iAuthFlow V2, a phishing toolkit that registers attacker-controlled passkeys to maintain persistent access even after victims reset passwords or revoke active sessions. This represents a novel persistence mechanism that bypasses traditional account recovery measures.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

Hackers Hide Agent Tesla JScript Behind Unicode Emojis to Evade Detection

Hackers hide Agent Tesla JScript malware behind Unicode emojis in BEC emails targeting finance teams. The obfuscated script mimics legitimate banking documents to evade detection and trick recipients into executing malware.

AI summary · generated with Claude
BECHighBusiness Email Compromiseemail compromise
Read original
Cyber Security News

Hackers Use Fake Google Gemini Installer to Deploy Vidar Stealer and Steal Browser Credentials

Cybercriminals disguise malware as a Google Gemini installer to distribute Vidar stealer, targeting saved browser passwords and credentials. The attack exploits routine software searches rather than email phishing, demonstrating credential-theft risks from trojanized downloads.

AI summary · generated with Claude
MalwareHighphishing
Read original
The Register

Russian snoops add OAuth abuse to targeted phishing campaigns

Russian cyber-spy groups are conducting targeted phishing campaigns against European and US academics, aerospace, defense, and government officials, abusing OAuth to enhance their attacks. Google has identified three distinct groups running ongoing operations with fewer than 100 targets each.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Def Con Attendees Targeted by Persistent Phishing Campaign

Def Con attendees were targeted by a persistent phishing campaign after the conference. Huntress researchers documented the elaborate scam, highlighting how threat actors leverage event attendance to conduct targeted phishing attacks against security professionals.

AI summary · generated with Claude
PhishingMediumphishing
Read original
Dark Reading

SilkParasite Threatens Central Asian Orgs With Flurry of RATs

A Chinese-nexus APT group linked to FamousSparrow is conducting spear-phishing campaigns targeting Central Asian organizations to deliver RATs, revealing China's strategic cyber operations in the region.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

Hackers Let Microsoft 365 Users Complete MFA, Then Steal Logged-In Sessions

Mirage2FA, a Phishing-as-a-Service platform, enables attackers to bypass Microsoft 365 MFA by allowing users to complete normal login, then stealing authenticated sessions via an adversary-in-the-middle attack. Thousands of compromise events have occurred since late 2024.

AI summary · generated with Claude
PhishingCriticalphishing
Read original
Cyber Security News

Hackers Use AI Voice Calls and Fake Banking Pages to Bypass MFA and Steal Accounts

Hackers use AI-generated voice calls paired with fake banking pages to bypass MFA and steal credentials from Mexican financial institutions. The Balonx Sistema campaign targets 20+ banks and has compromised 1,100+ accounts since October 2025 by requesting sensitive information during live phishing sessions.

AI summary · generated with Claude
PhishingCriticalphishing
Read original
The Hacker News

Phishing 3.0: The Fight Moves to Agent Versus Agent

Phishing tactics have evolved beyond payload-based detection toward AI-driven attacks where intent matters more than content. Traditional email defenses struggle as attackers increasingly use AI agents, requiring defenders to adopt new strategies.

AI summary · generated with Claude
PhishingHighphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.