Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

19 articles from HackRead
HackRead

Global Group Ransomware Abuses WinMerge to Deploy Encryptor

Global Group cybercriminals use payment-themed phishing emails delivering malicious ISO files and legitimate WinMerge tool to deploy ransomware against enterprises. Attackers establish persistence before encryption to facilitate extortion. This phishing-to-ransomware chain targets email security defenses.

AI summary · generated with Claude
PhishingHighphishing
Read original
HackRead

Revolut Customers Targeted by Phishing Campaign After Data Breach

Revolut customers face phishing attacks via text messages following a data breach that exposed personal information like IDs and selfies. Attackers are leveraging exposed data to conduct targeted phishing campaigns against financial service users.

AI summary · generated with Claude
PhishingHighphishing
Read original
HackRead

Fake OpenAI Billing Emails Target ChatGPT Users in Credential Phishing Scam

Phishing emails impersonating OpenAI billing notices are targeting ChatGPT users to steal credentials and payment details. Cofense researchers discovered the campaign. This directly threatens email users and demonstrates credential harvesting via email deception.

AI summary · generated with Claude
PhishingHighphishing
Read original
HackRead

New GhostCode Phishing Kit Hijacks Microsoft Accounts Despite MFA

Security researchers discovered the GhostCode phishing kit that exploits Microsoft OAuth to bypass MFA protections and steal credentials for Microsoft 365 accounts. The kit uses token-stealing techniques to gain unauthorized access despite multi-factor authentication being enabled, posing a significant threat to enterprise email security.

AI summary · generated with Claude
PhishingHighphishing
Read original
HackRead

Fake Sexual Misconduct Emails Target Universities with Zoho RAT

Phishing emails impersonating sexual misconduct allegations target universities, delivering fake Google Drive links that install Zoho RAT malware. Healthcare-linked institutions are primary targets. This demonstrates email's continued role as the primary attack vector for malware distribution.

AI summary · generated with Claude
PhishingHighphishing
Read original
HackRead

Hackers Stream Real Google Login Pages to Steal Passwords and 2FA Codes

Researchers discovered a phishing service streaming real Google login pages to attackers in real-time, enabling interception of passwords, 2FA codes, and authenticated sessions. This sophisticated credential-theft technique poses significant risk to organizations relying on Google Workspace for email and collaboration.

AI summary · generated with Claude
PhishingHighphishing
Read original
HackRead

How Hackers Use Email Addresses for Phishing and Account Takeover

Article explains how exposed email addresses facilitate phishing and account takeover attacks, detailing threat mechanisms and defensive practices. Directly addresses email-security risks and protection strategies relevant to security professionals managing email infrastructure and user security.

AI summary · generated with Claude
Phishingphishing
Read original
HackRead

MessiahGPT Criminal AI Service Advertised on BreachForums

MessiahGPT, an unrestricted criminal AI service, offers malware, phishing, and fraud capabilities on BreachForums. The platform provides 50 free queries and paid subscriptions from $8, representing a significant threat as it democratizes attack tools for cybercriminals targeting organizations.

AI summary · generated with Claude
PhishingHighphishing
Read original
HackRead

Kali365 Exploits Microsoft Device Login to Access US Corporate Data

Kali365 threat actor exploits Microsoft device login flows to obtain OAuth tokens for unauthorized corporate data access targeting US firms. SOC teams must enhance detection of phishing attacks leveraging this authentication bypass method.

AI summary · generated with Claude
PhishingHighphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.