Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

13 articles from The Register in Phishing
The Register

Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing

Salesforce Agentforce contained three critical vulnerabilities allowing attackers to hijack AI agents, steal CRM data without user interaction, and send phishing messages. Zenity Labs discovered the flaws and Salesforce has patched them, but the incident highlights risks in AI-driven business applications.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Register

BigBear phishing crew nets thousands of Microsoft 365 credentials

BigBear phishing crew harvested thousands of Microsoft 365 credentials and session cookies across hundreds of organizations. The operation, using Evilginx2-based phishing-as-a-service, captured hundreds of authenticated sessions capable of bypassing MFA. Researchers gained access to the attackers' admin panel, revealing unprecedented campaign details.

AI summary · generated with Claude
PhishingCriticalphishing
Read original
The Register

ASCII smuggling isn't just an AI security risk

Microsoft detected a massive phishing campaign using invisible Unicode characters (ASCII smuggling) to bypass email security filters, peaking at 2.37 million messages. Threat actors adapted AI-era techniques for traditional email phishing attacks. This highlights how obfuscation methods evolve to evade email defenses.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Register

Russian snoops add OAuth abuse to targeted phishing campaigns

Russian cyber-spy groups are conducting targeted phishing campaigns against European and US academics, aerospace, defense, and government officials, abusing OAuth to enhance their attacks. Google has identified three distinct groups running ongoing operations with fewer than 100 targets each.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Register

Attacker phished way into US defense supplier's Microsoft 365 account

An attacker phished a US defense supplier's employee to compromise their Microsoft 365 account. The attacker posed as a business contact and sent a fake Microsoft sharing link, gaining access to the organization's email environment and sensitive data.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Register

Russian spies take their half-click email attack from Zimbra to Outlook

Russian espionage group TA488 expanded its half-click phishing attacks from Zimbra to Microsoft Outlook Web Access, exploiting CVE-2026-42897 (XSS flaw in Exchange Server OWA). The attack requires minimal user interaction, posing significant risk to enterprise email environments.

AI summary · generated with Claude
PhishingHighCVE-2026-42897email attack
Read original
The Register

Kratos phishing-as-a-service kit loses its battle with international law enforcement

German law enforcement shut down Kratos, a widespread phishing-as-a-service kit, with support from US and Indonesian authorities. The operation targeted the infrastructure supporting one of the market's most dangerous PhaaS platforms and resulted in arrests. This disruption significantly impacts threat actors relying on Kratos for phishing campaigns.

AI summary · generated with Claude
Phishingphishing
Read original
The Register

AI spam filters are getting suckered by old-school text salting

Attackers are using text salting to evade AI-powered email filters by hiding benign words in phishing emails. Barracuda detected over one million retail-themed phishing attacks using this technique since April, showing that traditional obfuscation methods remain effective against modern defenses.

AI summary · generated with Claude
PhishingHighemail securityphishingspam
Read original
The Register

Fake IT bods on Microsoft Teams coax workers into installing malware

Cybercriminals impersonate IT support via Microsoft Teams to trick employees into installing EtherRAT malware. Attacks begin with phishing emails posing as employee surveys, followed by Teams calls requesting remote access. This targets organizations broadly through a multi-stage social engineering campaign.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Register

EvilTokens device-code phishing kit totally more evil than we all thought

EvilTokens device-code phishing kit bypasses MFA and authenticates to Microsoft 365 as victims. Cisco Talos revealed new evasion techniques and capabilities, highlighting the threat's sophistication to email security professionals managing organizational defense.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Register

Health board apologizes for phishing staff with with bogus vacation day

A Canadian health board conducted a phishing awareness test on staff using a fake vacation day offer, which sparked backlash for its inappropriate theme. The organization apologized for the social engineering exercise designed to test employee security awareness.

AI summary · generated with Claude
Phishingphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.