Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

8 articles from Cyber Security News in Phishing
Cyber Security News

7-Zip Mark-of-the-Web Bypass Lets Malicious Files Evade Windows SmartScreen

A 7-Zip vulnerability allows attackers to bypass Windows SmartScreen warnings by removing the Mark-of-the-Web indicator from extracted files. This is particularly dangerous in phishing campaigns where archives disguised as invoices or documents trick users into extraction, enabling malware execution without security prompts.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways

Phishing remains the primary breach vector, now enhanced by generative AI and account-takeover (AiTM) techniques that bypass email gateways and MFA. Top SOCs are adopting real-time behavioral detonation and threat intelligence to counter dynamic browser-based attacks that traditional email security cannot stop.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

A Fake Teams Update Can Give Hackers Two Separate Ways to Control Your PC

Operation BlueDash uses phishing emails falsely claiming document-sharing issues to trick users into installing a fake Microsoft Teams update, granting attackers dual remote-control capabilities. The campaign exploits email-based social engineering to deliver malware with multiple persistence mechanisms.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

Hackers Hijack 20+ Government Websites to Deliver Malware Through Trusted Links

PhantomEnigma campaign hijacks 20+ Brazilian government websites to distribute malware via trusted domains. Attackers compromised government mailboxes to send authenticated phishing emails bypassing SPF/DKIM/DMARC checks, targeting banking and public-sector organizations.

AI summary · generated with Claude
PhishingCriticalDKIMDMARCphishingSPF
Read original
Cyber Security News

Turkish Banks Targeted by 8,400 Phishing Domains and 6,600 Social Media Scam Ads

Turkish banks face a large-scale fraud campaign using 8,400 phishing domains and 6,600 social media scam ads to steal credentials and money. Attackers impersonate trusted financial brands through fake websites and social ads targeting customers with credential theft and fake loan offers.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

Hackers Abuse Microsoft Entra Passkey Enrollment to Hijack Enterprise Accounts

Threat group UNC066 has exploited Microsoft Entra passkey enrollment through phone-based phishing since April 2026, tricking employees into registering attacker-controlled passkeys to hijack enterprise accounts. The campaign combines social engineering with custom phishing kits targeting corporate credentials.

AI summary · generated with Claude
PhishingCriticalphishing
Read original
Cyber Security News

UNC6692 Hackers Uses Microsoft Teams Helpdesk Impersonation to Deploy SNOW Malware

UNC6692 threat group uses Microsoft Teams impersonation in spam emails to trick victims into installing SNOW malware. Attackers pose as IT helpdesk staff, exploiting social engineering and trust in familiar tools to gain machine control. This campaign targets organizations via email-based initial contact.

AI summary · generated with Claude
PhishingHighspam
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.