Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

7 articles from The Register in Phishing
The Register

Attacker phished way into US defense supplier's Microsoft 365 account

An attacker phished a US defense supplier's employee to compromise their Microsoft 365 account. The attacker posed as a business contact and sent a fake Microsoft sharing link, gaining access to the organization's email environment and sensitive data.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Register

Russian spies take their half-click email attack from Zimbra to Outlook

Russian espionage group TA488 expanded its half-click phishing attacks from Zimbra to Microsoft Outlook Web Access, exploiting CVE-2026-42897 (XSS flaw in Exchange Server OWA). The attack requires minimal user interaction, posing significant risk to enterprise email environments.

AI summary · generated with Claude
PhishingHighCVE-2026-42897email attack
Read original
The Register

Kratos phishing-as-a-service kit loses its battle with international law enforcement

German law enforcement shut down Kratos, a widespread phishing-as-a-service kit, with support from US and Indonesian authorities. The operation targeted the infrastructure supporting one of the market's most dangerous PhaaS platforms and resulted in arrests. This disruption significantly impacts threat actors relying on Kratos for phishing campaigns.

AI summary · generated with Claude
Phishingphishing
Read original
The Register

AI spam filters are getting suckered by old-school text salting

Attackers are using text salting to evade AI-powered email filters by hiding benign words in phishing emails. Barracuda detected over one million retail-themed phishing attacks using this technique since April, showing that traditional obfuscation methods remain effective against modern defenses.

AI summary · generated with Claude
PhishingHighemail securityphishingspam
Read original
The Register

Fake IT bods on Microsoft Teams coax workers into installing malware

Cybercriminals impersonate IT support via Microsoft Teams to trick employees into installing EtherRAT malware. Attacks begin with phishing emails posing as employee surveys, followed by Teams calls requesting remote access. This targets organizations broadly through a multi-stage social engineering campaign.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Register

EvilTokens device-code phishing kit totally more evil than we all thought

EvilTokens device-code phishing kit bypasses MFA and authenticates to Microsoft 365 as victims. Cisco Talos revealed new evasion techniques and capabilities, highlighting the threat's sophistication to email security professionals managing organizational defense.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Register

Health board apologizes for phishing staff with with bogus vacation day

A Canadian health board conducted a phishing awareness test on staff using a fake vacation day offer, which sparked backlash for its inappropriate theme. The organization apologized for the social engineering exercise designed to test employee security awareness.

AI summary · generated with Claude
Phishingphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.