Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

43 articles from The Hacker News in Phishing
The Hacker News

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

Phishing campaigns impersonate meeting invitations and software updates to trick users into installing MSP360 RMM software, which attackers then abuse to deploy ScreenConnect for dual-RMM control. This gives threat actors persistent remote access to compromised systems, affecting organizations relying on RMM tools.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

A US-focused phishing campaign targets C-suite executives, stealing Microsoft 365 sessions and deploying remote-access tools (RMM) for persistent compromise. Technology, manufacturing, government, and consulting sectors are heavily affected. This escalates phishing from credential theft to enterprise-wide account takeover.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

Microsoft disabled EvilTokens, an AI-powered device-code phishing service responsible for compromising approximately 12,000 inboxes. The takedown was coordinated with law enforcement and multiple tech companies. This represents a significant disruption to a major phishing-as-a-service operation targeting email accounts.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

SideCopy, an India-focused threat actor, has expanded targeting to academic institutions via spear-phishing campaigns using ReverseRAT malware. The group leverages mshta.exe abuse to execute malicious scripts and bypass security controls, broadening from government to education sector targets.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

RatHat is a China-based Android malware distributed via smishing and malvertising that uses AI for device control and persists through ADB abuse. It targets mobile devices with SMS phishing and fake app downloads, relevant to email security professionals monitoring phishing campaign vectors.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security

N0va phishkit targets US and EU businesses with sophisticated phishing campaigns impersonating trusted services to compromise legitimate accounts. Attackers bypass malware detection by leveraging valid credentials to access sensitive data and business systems, posing significant risk to organizations.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Threat actors sent over one million phishing emails impersonating CEOs to target Microsoft cloud accounts using passkey-themed social engineering. Attackers exploited third-party email infrastructure to deliver fraud messages and breached cloud environments to exfiltrate data, posing a significant risk to organizations.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

ThreatsDay roundup covers 200 Android flaws, browser-based phishing techniques, 119K scam shops, and other security incidents. Multiple stories highlight systemic failures where excessive permissions, trusted services exploited for phishing, and unpatched vulnerabilities enable attacks. Relevant to email security professionals monitoring phishing infrastructure and malware delivery mechanisms.

AI summary · generated with Claude
Phishingphishing
Read original
The Hacker News

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

Microsoft warns of a high-volume phishing campaign exploiting invisible Unicode characters to evade email filters. Attackers split keywords like 'funding' across special characters, bypassing detection while remaining visible to users, directly threatening email security infrastructure.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

ThreatsDay roundup covers multiple attack vectors including CEO phishing kits, compromised Dropbox accounts, and OAuth-based attacks. Attackers leverage legitimate-looking communications and trusted platforms to gain access, exploiting human trust rather than technical vulnerabilities.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries

A phishing campaign using Canadian tax forms has expanded to 46 countries, with 45% of attacks targeting the US. The campaign delivers Remote Monitoring and Management (RMM) malware via deceptive tax documents, representing a significant threat to organizations globally.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

NovaCookies, a $320/month AitM phishing toolkit, abuses legitimate DocuSign notifications to redirect Microsoft 365 logins and steal authenticated sessions. The subscription-based platform poses significant risk to organizations by compromising M365 credentials through email-based social engineering attacks.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

Criminals are using AI voice agents to impersonate Apple Support, targeting stolen-device owners to extract passcodes and 2FA codes via phishing calls. The AnonyMousKIT platform enables bypassing Apple's Activation Lock on stolen devices through a phishing-as-a-service model.

AI summary · generated with Claude
PhishingHighphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.