FBI、Microsoft OAuthトークンを標的としたフィッシング詐欺「Kali」に警告

FBIは、Microsoft OAuthトークンを標的とした「Kali365」と呼ばれる新しいフィッシングキットについて警告を発した。このキットはTelegram上で提供されており、AIが生成した誘い文句を利用している。

この警告では、Kali365が技術的スキルの低い攻撃者にとっての参入障壁をどのように引き下げているかを指摘している。同キットは、OAuthトークンを通じてMicrosoftアカウントを侵害可能な、AI生成のフィッシング用誘い文句へのアクセスを提供する。

関連記事

Illustration of a hacker exploiting Meta's AI chatbot to hijack Instagram accounts by changing email addresses and bypassing security.
AIによって生成された画像

Meta patches ai chatbot flaw used to hijack instagram accounts

AIによるレポート AIによって生成された画像

Hackers exploited Meta's AI support chatbot to take over Instagram accounts by tricking it into changing associated email addresses. The vulnerability allowed password resets without two-factor authentication after matching locations via VPN. Meta resolved the issue with an emergency patch on May 29.

Seventy-three Microsoft open source packages were compromised late last week with malware that steals credentials from cloud services and developer tools. The malicious code activates when opened in AI coding agents.

AIによるレポート

Microsoft has alerted users that hackers are targeting password reset processes to breach accounts. The activity is attributed to the group Storm-2949.

Developer platform Socket has identified a malware known as TrapDoor that is targeting crypto and AI developers.

AIによるレポート

A Hong Kong woman lost more than HK$1 million after being lured into a fraudulent cryptocurrency scheme through a fake artificial intelligence-powered trading app. Police recorded over 70 similar investment scams in the past week, with total losses exceeding HK$50 million.

このウェブサイトはCookieを使用します

サイトを改善するための分析にCookieを使用します。詳細については、プライバシーポリシーをお読みください。
拒否