Next-Gen Phishing Tactics Users Aren’t Ready For | Huntress
Move past basic credential harvesting. Discover how modern attackers use ClickFix, BitB, and OAuth consent phishing—and how to train your users with Huntress SAT.
Threat actors are impersonating web crawlers from major AI companies and enterprises by spoofing user agents to scan for and extract credentials and secrets from misconfigured servers. These automated scanners specifically target common locations where web servers inadvertently expose sensitive data, exploiting misconfigurations to harvest valuable information. GreyNoise Labs has identified this reconnaissance activity targeting OpenAI, Anthropic, DeepSeek, and Fortune 500 companies.
Read full article at GreyNoise Labs ↗Move past basic credential harvesting. Discover how modern attackers use ClickFix, BitB, and OAuth consent phishing—and how to train your users with Huntress SAT.
Get ready for a phishing trip! Learn about the strategy behind phishing simulations and how it can help your organization build resilience against real phishing threats.
Learn the essentials of phishing simulation training with our beginner's guide. Protect your organization by simulating real phishing attacks.
It’s getting cheaper and easier for cybercriminals to research potential victims. Here’s what’s still in your control.