Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

26 articles from The Hacker News
The Hacker News

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

Researchers discovered three attack methods bypassing passkey protections: exploiting Windows authentication material exposure, abusing cloud-synced passkeys via malware, and using phishing-resistant MFA workarounds. Passkeys are increasingly used for email account protection, making these attacks directly relevant to email security practitioners.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

UNC6671, a data extortion group, conducts vishing attacks on personal phones impersonating IT staff to trick enterprise employees into compromising SaaS credentials. The campaign targets financial services, private equity, and professional services sectors, bypassing traditional email security controls.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

Greatness PhaaS now supports device code phishing to bypass MFA and steal OAuth tokens. This technique abuses legitimate OAuth 2.0 Device Authorization Grant flows. Critical threat for organizations as attackers can compromise accounts despite MFA protections.

AI summary · generated with Claude
PhishingCriticalphishing
Read original
The Hacker News

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

HollowFrame loader and Matryoshka backdoor were deployed via spear-phishing targeting a law firm. The attack chain began with a phishing email containing a link to an encrypted archive with a malicious LNK file. This undocumented Go and Rust malware represents a sophisticated multi-stage threat.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

Device code phishing exploits OAuth 2.0 device authorization flows to steal access tokens at scale. Originally a red-team technique, it has become a widespread threat affecting various applications beyond input-constrained devices, posing significant risks to credential security and account access.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Operation BlueDash uses fake Microsoft Teams update lures to trick users into downloading legitimate RMM tools (Level and ScreenConnect), establishing remote access for potential credential harvesting or system compromise. This phishing campaign targets Teams users via compromised infrastructure and counterfeit Store pages.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

Cruciferra, a sophisticated crypter service, hides Windows malware using BYOVD and process ghosting techniques. The China-linked group uses it for tax-related phishing campaigns targeting Indian taxpayers and finance teams. The tool enables malware delivery while evading detection.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

Insurance phishing attacks have evolved from credential harvesting to real-time account hijacking, with attackers immediately compromising accounts during phishing sessions rather than storing credentials for later use. This represents a significant shift in attack tactics targeting financial institutions and insurance firms.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

North Korean threat actor BlueNoroff operates a phishing kit impersonating Zoom and Microsoft Teams to deliver malware. The campaign profiles cryptocurrency wallets before malware delivery, exploiting typosquatted domains to compromise targets through social engineering.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

A critical vulnerability in ChatGPT Workspace Agents (AgentForger) could allow attackers to deploy rogue AI agents via phishing links. The flaw enabled building and authorizing autonomous agents within victim organizations. OpenAI patched the issue as of June 8.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

Researchers at Rapid7 discovered an exposed server containing an AI-assisted phishing toolkit used in active malware campaigns. The toolkit, which includes lure templates and malware builders, was being deployed against Windows users in Mexico via WebDAV to deliver infostealers through spoofed government websites.

AI summary · generated with Claude
PhishingHighphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.