← Back
PhishingHelp Net Security·4 hours ago

Threat actors are posing as AI crawlers to hunt for exposed credentials

Threat actors are spoofing user-agent strings to impersonate AI crawlers from OpenAI, Anthropic, Google, Perplexity, and other companies while scanning websites for exposed credentials and configuration files. According to GreyNoise research, attackers exploit the fact that web requests are not authenticated by their user-agent declarations alone, making it trivial to forge legitimate-looking crawler identities. This technique allows adversaries to blend malicious reconnaissance traffic with legitimate AI indexing activity.

Read full article at Help Net Security

Related Articles

PhishingUnit 42·9 hours ago

Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

The Spring Ring campaign exploits Microsoft Teams as a vector for voice phishing attacks aimed at enterprise environments, with attackers using social engineering to gain access to sensitive systems. Researchers at Unit 42 have documented how this threat group leverages voice-based deception to ultimately deploy malware and target domain controllers within targeted organizations.

PhishingWired Security·3 days ago

Microsoft Teams Has Become a Haven for Scammers in China

Fraudsters are leveraging Microsoft Teams and other enterprise chat applications to conduct scams targeting Chinese victims, convincing them to transfer substantial funds. The exploitation of these widely-trusted business communication platforms has generated a surge in complaints, highlighting how scammers are adapting their tactics to abuse legitimate enterprise tools.

PhishingSentinelOne Labs·3 days ago

The Good, the Bad and the Ugly in Cybersecurity – Week 35

Authorities disrupted multiple global cybercrime rings this week, marking significant progress in international enforcement efforts. Attackers leveraged DocuSign in phishing campaigns associated with NovaCookies, exploiting trusted document services to increase credential theft effectiveness. Spark RAT activity was observed targeting Cambodia through exploitation of vulnerable drivers, demonstrating continued geographic-specific malware campaigns.