Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

37 articles from Infosecurity Magazine in Phishing
Infosecurity Magazine

Researchers Identify AliExpress Phishing Domains Before Registration

Security researchers at EfficientIP identified phishing domains impersonating AliExpress before registration completion, demonstrating proactive threat detection capabilities. This highlights the vulnerability of popular e-commerce brands to phishing attacks and the importance of domain monitoring for email security.

AI summary · generated with Claude
PhishingMediumphishing
Read original
Infosecurity Magazine

Revolut Customers Targeted with New Wave of Phishing Attacks

Revolut customers are experiencing a surge in phishing attacks following a recent data breach. Attackers are leveraging stolen customer data to craft convincing phishing messages. This represents a significant risk for email-based credential theft and fraud targeting financial services users.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Hackers Favor US Eastern Business Hours in M365 Phishing Campaign

KnowBe4 researchers identified a phishing campaign exploiting Microsoft 365's Direct Send feature to deliver malicious emails, with attackers timing submissions during US Eastern business hours to maximize impact and detection evasion.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials

CloudSEK discovered BigBear 2.0, a phishing-as-a-service campaign that has stolen over 5000 Microsoft credentials by targeting Microsoft 365 users. This threat directly affects email security as it leverages phishing to compromise email accounts and organizational infrastructure.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Outsider Phishing Kit Survives Takedown With 700 New Pages

A phishing kit called Outsider generated 700 new pages after Google led a takedown effort, demonstrating the threat actor's resilience and ability to quickly recreate malicious infrastructure.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign

A large-scale phishing campaign used SVG attachments disguised as voicemail notifications to evade email security controls. The attack targeted 5527 organizations with 26,000+ malicious messages, exploiting attachment-based delivery to breach email defenses.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

ZeroTokens Phishing Platform Steers Attacks in Real Time

ZeroTokens is a phishing platform enabling attackers to control victim sessions in real time, targeting 53 financial institutions. The tool allows dynamic attack steering, posing a significant threat to enterprise email security and authentication systems.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Fake Recruiter Scams Target Corporate Credentials on Mobile

RecruitTrap campaigns are using mobile-optimized phishing pages to impersonate recruiters and steal corporate credentials. The scam targets enterprise employees through mobile devices, attempting to harvest login credentials at scale.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Def Con Attendees Targeted by Persistent Phishing Campaign

Def Con attendees were targeted by a persistent phishing campaign after the conference. Huntress researchers documented the elaborate scam, highlighting how threat actors leverage event attendance to conduct targeted phishing attacks against security professionals.

AI summary · generated with Claude
PhishingMediumphishing
Read original
Infosecurity Magazine

Fake Bank of America Phishing Scam Installs Remote Access Malware

Cybercriminals are running a phishing campaign impersonating Bank of America to distribute malware that installs ScreenConnect remote access tools. The scam enables attackers to gain persistent system access and control compromised machines.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

AiTM Phishing Becomes Top Initial Access Threat to Law Firms

Adversary-in-the-Middle (AiTM) phishing has become the leading initial access vector for law firms, accounting for 56% of threats. This technique bypasses multi-factor authentication by intercepting credentials in real-time, posing severe risks to organizations handling sensitive client data.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages

Attackers used Teams-themed phishing to abuse Microsoft's legitimate login pages rather than hosting fake ones, making detection harder. Check Point researchers documented this campaign targeting users. This represents an evolution in phishing tactics that security professionals need to identify and defend against.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

LogoKit Phishing Kit Screenshots Victim Sites in Real Time

LogoKit phishing kit now generates victim-specific phishing pages using real-time screenshots of target websites, making phishing attacks more convincing and harder to detect. This advancement increases phishing campaign effectiveness against email recipients.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

ChatGPT Among Top 10 Most Impersonated Brands in Phishing Attacks, Says Check Point

ChatGPT entered the top 10 most impersonated brands in phishing attacks according to Check Point research. Attackers are leveraging the brand's popularity to deceive users. This represents a growing threat vector email security professionals must monitor and defend against.

AI summary · generated with Claude
PhishingHighphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.