Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

49 articles from The Hacker News
The Hacker News

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

Phishing campaigns impersonate meeting invitations and software updates to trick users into installing MSP360 RMM software, which attackers then abuse to deploy ScreenConnect for dual-RMM control. This gives threat actors persistent remote access to compromised systems, affecting organizations relying on RMM tools.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

A US-focused phishing campaign targets C-suite executives, stealing Microsoft 365 sessions and deploying remote-access tools (RMM) for persistent compromise. Technology, manufacturing, government, and consulting sectors are heavily affected. This escalates phishing from credential theft to enterprise-wide account takeover.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

Microsoft disabled EvilTokens, an AI-powered device-code phishing service responsible for compromising approximately 12,000 inboxes. The takedown was coordinated with law enforcement and multiple tech companies. This represents a significant disruption to a major phishing-as-a-service operation targeting email accounts.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

SideCopy, an India-focused threat actor, has expanded targeting to academic institutions via spear-phishing campaigns using ReverseRAT malware. The group leverages mshta.exe abuse to execute malicious scripts and bypass security controls, broadening from government to education sector targets.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

RatHat is a China-based Android malware distributed via smishing and malvertising that uses AI for device control and persists through ADB abuse. It targets mobile devices with SMS phishing and fake app downloads, relevant to email security professionals monitoring phishing campaign vectors.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security

N0va phishkit targets US and EU businesses with sophisticated phishing campaigns impersonating trusted services to compromise legitimate accounts. Attackers bypass malware detection by leveraging valid credentials to access sensitive data and business systems, posing significant risk to organizations.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

Cisco Secure Email Gateway has a critical vulnerability (CVE-2026-76461) with a 9.8 CVSS score in AsyncOS email parsing logic. Unauthenticated remote attackers can exploit it for root command execution. Active exploitation in the wild poses immediate risk to email infrastructure.

AI summary · generated with Claude
VulnerabilityCriticalCVE-2026-76461secure email gateway
Read original
The Hacker News

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Threat actors sent over one million phishing emails impersonating CEOs to target Microsoft cloud accounts using passkey-themed social engineering. Attackers exploited third-party email infrastructure to deliver fraud messages and breached cloud environments to exfiltrate data, posing a significant risk to organizations.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

ThreatsDay roundup covers 200 Android flaws, browser-based phishing techniques, 119K scam shops, and other security incidents. Multiple stories highlight systemic failures where excessive permissions, trusted services exploited for phishing, and unpatched vulnerabilities enable attacks. Relevant to email security professionals monitoring phishing infrastructure and malware delivery mechanisms.

AI summary · generated with Claude
Phishingphishing
Read original
The Hacker News

Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

Autonomous AI agents were used by threat actors to compromise thousands of credentials in under six hours. Google's Threat Intelligence Group observed attackers leveraging a multi-agent framework for large-scale credential harvesting. This represents an escalation in AI-driven attacks that could impact email security defenses.

AI summary · generated with Claude
Highcredential harvesting
Read original
The Hacker News

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

Attackers are exploiting compromised ScreenConnect clients to distribute a four-stage VBScript malware payload to newly connected systems. Initial compromise vectors include tech-support scams, phishing emails with MSI installers, and fake applications. This affects organizations using ScreenConnect and represents a significant supply-chain-like threat via remote access software.

AI summary · generated with Claude
MalwareHighphishing
Read original
The Hacker News

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

JSCeal, a sophisticated JavaScript malware, can steal session cookies to bypass Google Authentication and conduct surveillance. It features credential harvesting, traffic interception, and multiple obfuscation techniques. This poses significant risk to email users and organizations relying on email-based authentication.

AI summary · generated with Claude
MalwareHighcredential harvesting
Read original
The Hacker News

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

Microsoft warns of a high-volume phishing campaign exploiting invisible Unicode characters to evade email filters. Attackers split keywords like 'funding' across special characters, bypassing detection while remaining visible to users, directly threatening email security infrastructure.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

ThreatsDay roundup covers multiple attack vectors including CEO phishing kits, compromised Dropbox accounts, and OAuth-based attacks. Attackers leverage legitimate-looking communications and trusted platforms to gain access, exploiting human trust rather than technical vulnerabilities.

AI summary · generated with Claude
PhishingHighphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.