Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

107 articles in Phishing
Infosecurity Magazine

Interpol Dismantles SniperDz Phishing-as-a-Service Platform

Interpol dismantled SniperDz, a decade-old phishing-as-a-service platform exposed by Group-IB. The operation provided phishing infrastructure to cybercriminals targeting organizations globally. This takedown is significant for email security professionals as it disrupts a major phishing distribution network.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cofense

Fast, Accurate, Compliant: The New Standard for Email Security

Cofense discusses the evolving email threat landscape, including AI-enabled phishing, BEC, and ransomware, while highlighting how cybersecurity teams must balance sophisticated threats with increasing regulatory compliance requirements.

AI summary · generated with Claude
PhishingBECBusiness Email Compromiseemail compromiseemail securityphishing
Read original
Cofense

The Real Problem With “Spot the Phish” Training in 2026

The article critiques 'spot the phish' email security training, arguing it's outdated because modern phishing attacks lack obvious visual red flags. As phishing techniques become more sophisticated, traditional user-awareness models fail to protect organizations effectively.

AI summary · generated with Claude
Phishingphishing
Read original
Cofense

Why Traditional Phishing “Red Flags” Fail Against AI-Generated Attacks

AI-powered phishing attacks now bypass traditional red flags by generating grammatically correct, contextually relevant emails tailored to specific targets. Classic awareness training focused on poor grammar and generic greetings is insufficient against sophisticated AI-crafted messages. Security professionals must adapt detection and training strategies accordingly.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Attackers Abuse Shared Content for ChatGPT Phishing Campaign

Attackers are exploiting ChatGPT's shared content feature to deliver malware in phishing campaigns. Threat actors use the chatgpt.com/s/ domain to host malicious files, leveraging the trusted platform to bypass security controls. This poses a risk to organizations relying on email-based threat detection.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Thousands of Fake FIFA Domains Target World Cup Fans

Group-IB discovered 4,300 fake FIFA World Cup domains and a phishing campaign called Ghost Stadium targeting fans during the World Cup. These fraudulent domains impersonate legitimate FIFA services to harvest credentials and personal data from victims.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

BTMOB Android RAT Spreads Through No-Code Builder Tooling

BTMOB Android RAT is a remote access trojan distributed as a service with a no-code builder enabling rapid creation of region-specific phishing lures. The threat primarily targets Android devices through phishing campaigns. This affects email security professionals who must monitor phishing emails delivering Android malware payloads.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Iran-Linked Hackers Target US Aviation with Phishing and SEO Poisoning Campaign

Iran-linked Nimbus Manticore launched phishing and SEO poisoning attacks targeting US aviation sector to distribute the AI-built MiniFast backdoor. Email-based phishing remains a key delivery vector for this advanced persistent threat against critical infrastructure.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

FBI Warns 'Kali365' Phishing Kit Hijacks Microsoft 365 OAuth Tokens

The FBI warns of Kali365, a phishing-as-a-service platform that targets Microsoft 365 OAuth tokens, lowering barriers for cybercriminals. The attack directly compromises email and cloud accounts, making it a critical threat to defenders managing M365 environments.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Researchers Spot Uptick in Use of Vercel for Phishing Campaigns

Researchers detected a significant rise in phishing campaigns exploiting Vercel's platform to host malicious content. Attackers leverage Vercel's legitimate hosting service to bypass email security controls and increase campaign credibility. This trend highlights how threat actors abuse trusted infrastructure to improve phishing delivery and evasion.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Microsoft Flags Mass Phishing Campaign Using Fake Compliance Emails

Microsoft detected a large-scale phishing campaign using fake compliance emails to steal credentials from 35,000 users across 13,000 organizations globally. The attack demonstrates how threat actors abuse common organizational compliance processes to deceive targets into surrendering sensitive information.

AI summary · generated with Claude
PhishingHighphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.