Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

121 articles
Cofense

The Platform You Trust Is the Platform They Target

Threat actors are shifting from generic phishing campaigns to platform-aware attacks that adapt malware delivery based on the victim's device, browser, and environment. This evolution targets Windows, macOS, and other platforms with selective credential phishing, RATs, or malware payloads, requiring defenders to strengthen detection across multiple endpoints.

AI summary · generated with Claude
PhishingHighphishing
Read original
HackRead

New EvilTokens Attack Exposes Browser Visibility Gap in Enterprise SOCs

EvilTokens is a phishing attack that hides account takeover indicators until browser execution, leaving SOCs with limited visibility. Enterprise teams need enhanced monitoring to validate threats faster and reduce account compromise risk.

AI summary · generated with Claude
PhishingHighphishing
Read original
Proofpoint

Defending the Authentication Flow: Device Code Phishing with Selena Larson

Proofpoint discusses device code phishing attacks where attackers bypass authentication mechanisms using OAuth device flows. This threat targets users' authentication credentials and could enable account compromise, making it relevant for email security professionals handling credential-based threats.

AI summary · generated with Claude
PhishingMediumphishing
Read original
Infosecurity Magazine

Hackers Leverage Blockchain to Hit Japan's Hotels Through Booking.com Phishing

Hackers sent phishing emails to Japanese hotels partnered with Booking.com in May, distributing malware hosted on blockchain networks. The campaign targeted accommodation partners through credential-stealing phishing, enabling unauthorized access to booking accounts and guest data.

AI summary · generated with Claude
PhishingHighphishing
Read original
CyberScoop

How ransomware syndicates weaponize corporate-style organization

Black Basta ransomware syndicate operates like a sophisticated corporation, using advanced phishing and malware campaigns to target victims. The group's leaked internal communications reveal their evolution into organized extortion operations, relevant to understanding modern ransomware delivery mechanisms.

AI summary · generated with Claude
MalwareHighphishing
Read original
Infosecurity Magazine

FBI Sounds Alarm Over Russian Intelligence Signal Phishing

The FBI warns that Russian intelligence actors are conducting phishing campaigns to steal Signal backup encryption keys. This targets users' end-to-end encrypted communications. Email security professionals should monitor for phishing emails luring users to compromise their encrypted messaging credentials.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cofense

Security Is No Longer an IT Problem: Why Boards Must Rethink Cyber Resilience in the Age of AI

AI-powered phishing attacks now evade traditional email security tools through polymorphic campaigns that continuously evolve. Organizations must adopt board-level cyber resilience strategies beyond IT-focused security gateways and filters to combat adaptive threats.

AI summary · generated with Claude
PhishingHighemail securityphishingsecure email gateway
Read original
The Register

Health board apologizes for phishing staff with with bogus vacation day

A Canadian health board conducted a phishing awareness test on staff using a fake vacation day offer, which sparked backlash for its inappropriate theme. The organization apologized for the social engineering exercise designed to test employee security awareness.

AI summary · generated with Claude
Phishingphishing
Read original
Cofense

World Cup-Themed Phishing Campaign Delivers Voidrift Malware with Highly Personalized Lures

Cofense discovered a phishing campaign using FIFA World Cup 2026 lures to deliver Voidrift malware. Emails are highly personalized with recipient and company details, indicating extensive reconnaissance. The campaign demonstrates sophisticated social engineering tactics targeting organizations.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Serverless Phishing Kit on GitHub Targets Mexican Banks

A serverless phishing kit named GitBait exploits GitHub Pages and SheetBest API to target Mexican banks and steal credentials. The kit leverages hosting and data aggregation services to facilitate credential theft at scale.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cofense

Phishing No Longer Looks Wrong: What Security Leaders Should Do Next

Modern phishing attacks using AI-generated, polymorphic messages increasingly look legitimate and avoid static detection, requiring security leaders to move beyond prevention-focused defenses to adopt new strategies for detecting and responding to sophisticated social engineering.

AI summary · generated with Claude
PhishingHighmalicious emailphishing
Read original
Infosecurity Magazine

Interpol Dismantles SniperDz Phishing-as-a-Service Platform

Interpol dismantled SniperDz, a decade-old phishing-as-a-service platform exposed by Group-IB. The operation provided phishing infrastructure to cybercriminals targeting organizations globally. This takedown is significant for email security professionals as it disrupts a major phishing distribution network.

AI summary · generated with Claude
PhishingHighphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.