Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

5 articles from ISC SANS
ISC SANS

One URL, Three Different Tricks, (Thu, Sep 24th)

A phishing email uses a specially crafted URL designed to bypass security controls through obfuscation techniques. The URL structure employs multiple tricks to evade detection while appearing as garbage to basic defenses. Email security professionals should understand these evasion tactics.

AI summary · generated with Claude
PhishingMediumphishing
Read original
ISC SANS

A polymorphic phishing page (that occasionally breaks itself), (Thu, Aug 27th)

A security researcher documents a polymorphic phishing page that dynamically changes appearance to evade detection. The attacker's code occasionally malfunctions, causing the phishing page to break. This demonstrates obfuscation techniques used in active phishing campaigns.

AI summary · generated with Claude
PhishingMediumphishingspam
Read original
ISC SANS

Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)

Phishing campaigns are targeting AI solutions providers by impersonating AI services like ChatGPT. Attackers exploit users' fear of losing access or data to deliver phishing emails. This represents an emerging threat vector leveraging the popularity of AI platforms.

AI summary · generated with Claude
PhishingHighphishing
Read original
ISC SANS

"Comment stuffing" in an HTML phishing attachment as a mechanism for evading AI-based detection?, (Fri, Jul 10th)

Security researchers identified a phishing technique using HTML comment stuffing to evade AI-based email detection systems. This method obscures phishing content within HTML comments, representing an evolving evasion tactic that email security professionals should monitor for detection bypass attempts.

AI summary · generated with Claude
PhishingHighphishing
Read original
ISC SANS

Why Ask Credentials If There Are Secret Codes?, (Wed, Jul 1st)

A phishing campaign targeting MetaMask cryptocurrency wallet users was detected. The attack uses alternative authentication methods instead of traditional credential theft, demonstrating evolving phishing tactics that security professionals should recognize.

AI summary · generated with Claude
PhishingMediumphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.