Email threat intelligence for security teams

MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.

A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.

This week in email security

AI briefing · 2026-08-30

Phishing-as-a-service kits and credential-theft campaigns surge across Microsoft 365 and mobile

144 articles
Infosecurity Magazine

Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign

A large-scale phishing campaign used SVG attachments disguised as voicemail notifications to evade email security controls. The attack targeted 5527 organizations with 26,000+ malicious messages, exploiting attachment-based delivery to breach email defenses.

AI summary · generated with Claude
PhishingHighphishing
Read original
ISC SANS

A polymorphic phishing page (that occasionally breaks itself), (Thu, Aug 27th)

A security researcher documents a polymorphic phishing page that dynamically changes appearance to evade detection. The attacker's code occasionally malfunctions, causing the phishing page to break. This demonstrates obfuscation techniques used in active phishing campaigns.

AI summary · generated with Claude
PhishingMediumphishingspam
Read original
The Hacker News

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

NovaCookies, a $320/month AitM phishing toolkit, abuses legitimate DocuSign notifications to redirect Microsoft 365 logins and steal authenticated sessions. The subscription-based platform poses significant risk to organizations by compromising M365 credentials through email-based social engineering attacks.

AI summary · generated with Claude
PhishingHighphishing
Read original
Dark Reading

'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month

NovaCookies is a phishing-as-a-service kit enabling attackers to conduct adversary-in-the-middle attacks against Microsoft 365 users, stealing session cookies beyond credentials for $320/month. This lowers the attack complexity for email-based credential harvesting campaigns targeting enterprise cloud environments.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

Criminals are using AI voice agents to impersonate Apple Support, targeting stolen-device owners to extract passcodes and 2FA codes via phishing calls. The AnonyMousKIT platform enables bypassing Apple's Activation Lock on stolen devices through a phishing-as-a-service model.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

ZeroTokens Phishing Platform Steers Attacks in Real Time

ZeroTokens is a phishing platform enabling attackers to control victim sessions in real time, targeting 53 financial institutions. The tool allows dynamic attack steering, posing a significant threat to enterprise email security and authentication systems.

AI summary · generated with Claude
PhishingHighphishing
Read original
Infosecurity Magazine

Fake Recruiter Scams Target Corporate Credentials on Mobile

RecruitTrap campaigns are using mobile-optimized phishing pages to impersonate recruiters and steal corporate credentials. The scam targets enterprise employees through mobile devices, attempting to harvest login credentials at scale.

AI summary · generated with Claude
PhishingHighphishing
Read original
The Hacker News

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

Mirage2FA, a phishing-as-a-service toolkit, compromised 4,500+ US and EU companies by abusing Microsoft 365 login flows to bypass 2FA. The campaign affected 48% of targeted email addresses. This directly impacts email security professionals defending against credential theft and account takeover attacks.

AI summary · generated with Claude
PhishingCriticalphishing
Read original
The Hacker News

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

Attackers exploited 24 npm packages to host fake Cloudflare CAPTCHA pages for phishing attacks. The malicious packages leverage unpkg mirrors as free infrastructure to redirect users to ClickFix-style scam pages. This highlights supply chain risks where legitimate package repositories enable phishing campaigns.

AI summary · generated with Claude
PhishingHighphishing
Read original
SecurityWeek

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

ReliaQuest confirmed that ShinyHunters hackers exploited a phishing-compromised employee account to access a dashboard, though the company states the impact was limited. This incident demonstrates the persistent threat of phishing targeting enterprise security firms.

AI summary · generated with Claude
PhishingMediumphishing
Read original
SecurityWeek

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

Researchers discovered iAuthFlow V2, a phishing toolkit that registers attacker-controlled passkeys to maintain persistent access even after victims reset passwords or revoke active sessions. This represents a novel persistence mechanism that bypasses traditional account recovery measures.

AI summary · generated with Claude
PhishingHighphishing
Read original
Cyber Security News

Hackers Hide Agent Tesla JScript Behind Unicode Emojis to Evade Detection

Hackers hide Agent Tesla JScript malware behind Unicode emojis in BEC emails targeting finance teams. The obfuscated script mimics legitimate banking documents to evade detection and trick recipients into executing malware.

AI summary · generated with Claude
BECHighBusiness Email Compromiseemail compromise
Read original
Cyber Security News

Hackers Use Fake Google Gemini Installer to Deploy Vidar Stealer and Steal Browser Credentials

Cybercriminals disguise malware as a Google Gemini installer to distribute Vidar stealer, targeting saved browser passwords and credentials. The attack exploits routine software searches rather than email phishing, demonstrating credential-theft risks from trojanized downloads.

AI summary · generated with Claude
MalwareHighphishing
Read original
The Register

Russian snoops add OAuth abuse to targeted phishing campaigns

Russian cyber-spy groups are conducting targeted phishing campaigns against European and US academics, aerospace, defense, and government officials, abusing OAuth to enhance their attacks. Google has identified three distinct groups running ongoing operations with fewer than 100 targets each.

AI summary · generated with Claude
PhishingHighphishing
Read original

Get the weekly briefing in your inbox

The week's most important email-security news, curated and summarized — every Monday morning. No tracking, one-click unsubscribe.