Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

16 articles from Dark Reading
Dark Reading

Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net

Russia's Star Blizzard APT group has abandoned ClickFix attacks for a new "RedFlick" phishing tactic targeting Ukrainian organizations. The campaign delivers the CosmicPulse backdoor to NGOs, think tanks, and journalists, representing an evolution in their phishing delivery methods and a direct threat to email security defenses.

AI summary · generated with Claude
PhishingHighphishing
Read original
Dark Reading

'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing

Researchers discovered 'Salesbleed,' an attack that exploits Salesforce Agents to inject malicious instructions into Slack, enabling phishing attacks through trusted internal communication channels. This demonstrates how agentic AI systems can be manipulated to deliver harmful payloads across integrated business applications, posing risks to enterprise messaging security.

AI summary · generated with Claude
PhishingHighphishing
Read original
Dark Reading

Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign

Attackers are poisoning AI chatbots by seeding the web with malicious links and data, which are then displayed in ChatGPT, Gemini, and Google AI responses. This technique facilitates mass disinformation and phishing campaigns targeting users who trust AI-generated answers.

AI summary · generated with Claude
PhishingHighphishing
Read original
Dark Reading

Microsoft Disrupts EvilTokens Device Code Phishing Service

Microsoft disrupted EvilTokens, a phishing-as-a-service platform targeting Microsoft 365 accounts, by seizing 50 websites and disabling 150+ domains. The action targets automated credential theft attacks leveraging device code authentication flows. This matters to security professionals managing email and cloud identity threats.

AI summary · generated with Claude
PhishingHighphishing
Read original
Dark Reading

Threat Actor Generates 1M Personalized Fraud Emails in 3 Days

A threat actor generated 1 million personalized fraudulent emails in 3 days using AI, enabling attackers to scale phishing/BEC campaigns without sacrificing personalization. This significantly lowers the barrier for effective email-based fraud attacks targeting security defenders and their organizations.

AI summary · generated with Claude
PhishingHighmalicious email
Read original
Dark Reading

Attackers Use Multi-Hop Google Redirects for Phishing Campaign

Attackers are leveraging multi-hop Google redirects to bypass security filters in phishing campaigns designed to steal credentials or deploy ScreenConnect malware. This technique exploits Google's trusted reputation to evade detection systems.

AI summary · generated with Claude
PhishingHighphishing
Read original
Dark Reading

Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites

Cybercriminals compromised Brazilian government servers to host phishing sites, leveraging a reverse-proxy network with gambling themes. A Chinese-language group is behind the campaign, targeting government and education infrastructure for malicious hosting.

AI summary · generated with Claude
PhishingHighphishing
Read original
Dark Reading

'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month

NovaCookies is a phishing-as-a-service kit enabling attackers to conduct adversary-in-the-middle attacks against Microsoft 365 users, stealing session cookies beyond credentials for $320/month. This lowers the attack complexity for email-based credential harvesting campaigns targeting enterprise cloud environments.

AI summary · generated with Claude
PhishingHighphishing
Read original
Dark Reading

SilkParasite Threatens Central Asian Orgs With Flurry of RATs

A Chinese-nexus APT group linked to FamousSparrow is conducting spear-phishing campaigns targeting Central Asian organizations to deliver RATs, revealing China's strategic cyber operations in the region.

AI summary · generated with Claude
PhishingHighphishing
Read original
Dark Reading

Device Code Phishing Up 1,500% in 2026; Vishing Doubles

Device code phishing attacks surged 1,500% in 2026, while vishing (voice phishing) doubled. These social engineering techniques bypass traditional security controls and minimize forensic traces.

AI summary · generated with Claude
PhishingHighphishing
Read original
Dark Reading

Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets

Russian hackers exploit a Zimbra zero-day vulnerability, sending "half-click" phishing emails requiring only message preview to compromise US and Ukraine targets. The state-sponsored group Laundry Bear leverages this technique for low-friction exploitation.

AI summary · generated with Claude
PhishingCriticalphishing
Read original
Dark Reading

Attackers Combo Up Evasion Tactics for BEC Phishing

Attackers are combining evasion tactics including fileless techniques and loaders to deploy RATs and stealers in BEC phishing campaigns. This sophisticated approach achieves low detection rates, making it harder for email security systems to catch these threats before they reach users.

AI summary · generated with Claude
BECHighBECphishing
Read original
Dark Reading

1M+ Emails Use Hidden Text to Dupe AI Security Filters

Attackers are using text salting techniques to hide content in over 1 million phishing emails, exploiting weaknesses in AI-based email security filters. This attack method renders AI and large language models ineffective at detecting malicious messages, allowing them to bypass protection systems.

AI summary · generated with Claude
PhishingHighphishing
Read original
Dark Reading

Turning the Tables on Email Scammers With 'ScamBuster'

An open-source AI system called 'ScamBuster' uses victim personas to engage phishing attackers, enabling organizations and law enforcement to gather intelligence on criminal operations. This defensive tool helps turn the tables on email scammers by collecting operational data.

AI summary · generated with Claude
Phishingphishing
Read original
Dark Reading

Big Brand Jobs Scam Targets Marketing Pros' Google Accounts

A phishing campaign impersonating job opportunities from major brands targets marketing professionals to steal their Google account credentials using nested redirects and evasion techniques.

AI summary · generated with Claude
PhishingHighphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.