Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

229 articles
Infosecurity Magazine

Fake Bank of America Phishing Scam Installs Remote Access Malware

Cybercriminals are running a phishing campaign impersonating Bank of America to distribute malware that installs ScreenConnect remote access tools. The scam enables attackers to gain persistent system access and control compromised machines.

AI summary · generated with Claude
PhishingHighphishing
Read original
HackRead

Kali365 Exploits Microsoft Device Login to Access US Corporate Data

Kali365 threat actor exploits Microsoft device login flows to obtain OAuth tokens for unauthorized corporate data access targeting US firms. SOC teams must enhance detection of phishing attacks leveraging this authentication bypass method.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

Greatness PhaaS now supports device code phishing to bypass MFA and steal OAuth tokens. This technique abuses legitimate OAuth 2.0 Device Authorization Grant flows. Critical threat for organizations as attackers can compromise accounts despite MFA protections.

AI summary · generated with Claude
PhishingCriticalphishing
Read original
Cyber Security News

Hackers Can Weaponize Microsoft Copilot to Hijack CEO Accounts and Redirect Wire Transfers

Researchers demonstrated how Microsoft Copilot in Microsoft 365 can be weaponized for business email compromise (BEC) and wire fraud. A single compromised employee account can escalate to CEO takeover and steal $250,000 with minimal attacker effort, posing significant risk to email security.

AI summary · generated with Claude
BECHighBECBusiness Email Compromiseemail compromise
Read original
Cyber Security News

How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways

Phishing remains the primary breach vector, now enhanced by generative AI and account-takeover (AiTM) techniques that bypass email gateways and MFA. Top SOCs are adopting real-time behavioral detonation and threat intelligence to counter dynamic browser-based attacks that traditional email security cannot stop.

AI summary · generated with Claude
PhishingHighphishing
Read original
Dark Reading

Device Code Phishing Up 1,500% in 2026; Vishing Doubles

Device code phishing attacks surged 1,500% in 2026, while vishing (voice phishing) doubled. These social engineering techniques bypass traditional security controls and minimize forensic traces.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cofense

Why Campaign-Level Phishing Defense Is the Future of Email Security

AI-driven phishing campaigns now employ coordinated variations to evade traditional detection. Campaign-level defense strategies are necessary as threat actors generate thousands of unique email variants serving shared objectives, fundamentally changing email security approaches.

AI summary · generated with Claude
PhishingHighemail securitymalicious emailphishing
Read original
ISC SANS

Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)

Phishing campaigns are targeting AI solutions providers by impersonating AI services like ChatGPT. Attackers exploit users' fear of losing access or data to deliver phishing emails. This represents an emerging threat vector leveraging the popularity of AI platforms.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

HollowFrame loader and Matryoshka backdoor were deployed via spear-phishing targeting a law firm. The attack chain began with a phishing email containing a link to an encrypted archive with a malicious LNK file. This undocumented Go and Rust malware represents a sophisticated multi-stage threat.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

Device code phishing exploits OAuth 2.0 device authorization flows to steal access tokens at scale. Originally a red-team technique, it has become a widespread threat affecting various applications beyond input-constrained devices, posing significant risks to credential security and account access.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

AiTM Phishing Becomes Top Initial Access Threat to Law Firms

Adversary-in-the-Middle (AiTM) phishing has become the leading initial access vector for law firms, accounting for 56% of threats. This technique bypasses multi-factor authentication by intercepting credentials in real-time, posing severe risks to organizations handling sensitive client data.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages

Attackers used Teams-themed phishing to abuse Microsoft's legitimate login pages rather than hosting fake ones, making detection harder. Check Point researchers documented this campaign targeting users. This represents an evolution in phishing tactics that security professionals need to identify and defend against.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Register

Russian spies take their half-click email attack from Zimbra to Outlook

Russian espionage group TA488 expanded its half-click phishing attacks from Zimbra to Microsoft Outlook Web Access, exploiting CVE-2026-42897 (XSS flaw in Exchange Server OWA). The attack requires minimal user interaction, posing significant risk to enterprise email environments.

AI summary · generated with Claude
PhishingHighCVE-2026-42897email attack
Read original
Infosecurity Magazine

LogoKit Phishing Kit Screenshots Victim Sites in Real Time

LogoKit phishing kit now generates victim-specific phishing pages using real-time screenshots of target websites, making phishing attacks more convincing and harder to detect. This advancement increases phishing campaign effectiveness against email recipients.

AI summary · generated with Claude
PhishingHighphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.