LIVE · cybersecurity feed
Live wire
CVE-2026-15409 · Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeterAnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodesCVE-2026-60004 · Hackers now exploit critical Gitea flaw in code injection attacksEmployee benefits platform Paylogix says hackers stole financial and health dataU.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure BreachesCVE-2026-61979 · Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as VulnerableCVE-2024-28224 · A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClawAustralia Warns of Active Exploitation of Critical TeamCity Server FlawCVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attack
phishingcritical

AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes

A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar found. “By leveraging a critical flaw – the use of bare relative paths – the investigation unraveled a reseller supply chain of 506 domains and 168 storefront brands active since early 2024. Despite leveraging advanced AI to mim

zeroday.news ·

A new phishing-as-a-service (PhaaS) platform, dubbed AnonyMousKIT, is actively being used to automate the theft of Apple ID credentials, which are necessary to bypass the Activation Lock feature on stolen iPhones. The platform leverages advanced AI voice calls to impersonate Apple Support and trick victims into revealing their device passcodes and other sensitive information.

An investigation into AnonyMousKIT revealed a reseller supply chain comprising 506 domains and 168 distinct storefront brands, which have been operational since early 2024. Researchers uncovered these connections by exploiting a critical flaw in the platform's design: the use of bare relative paths, which inadvertently exposed production logs and operator rosters.

The platform's operation is designed to monetize stolen devices by providing a service for thieves who lack the technical skills to bypass Apple's Activation Lock themselves. This security feature, introduced in iOS 7, links an iPhone to its owner's Apple ID when Find My is enabled, preventing unauthorized use even after a factory reset.

AnonyMousKIT subscribers initiate an attack by entering a stolen device's serial number or IMEI into the platform. The system then retrieves information about the device, including its model and current Find My status. This data is used to craft highly targeted phishing messages, delivered via email, SMS, WhatsApp, recorded calls, or live voice agents.

The phishing attempts are particularly effective because they target recent victims of device theft or loss, exploiting their active search efforts and leveraging accurate hardware data. Victims receive messages claiming their device has been found and asking them to verify their identity to retrieve it.

In calls reviewed by researchers, AI voice agents, often using the persona "Alice Dias, Apple Support," tell victims that someone attempted to unlock their phone at an Apple store, and the store is now holding it for security reasons. The agent follows a predefined script, beginning by confirming device ownership and then requesting the victim's four- or six-digit passcode.

After obtaining the passcode, the agent continues the narrative, claiming a recovery case has been opened and asking if the victim received a security link via text. If not, the agent resends the link and guides the victim through entering the unlock code from it. Once the code is confirmed, the call concludes. The stolen credentials can then be used to remove Activation Lock, allowing the device to be resold.

Researchers recovered 200 call logs and 55 transcripts from the voice agents. Of these, 179 calls were directed to Brazil, incurring a total cost of $19.24. The platform supports five voice-agent personas configured in English, Spanish, and Brazilian Portuguese.

AnonyMousKIT is structured in tiers, with a developer creating and selling the platform, buyers licensing it for their branded storefronts, and operators underneath them dispatching phishing messages. Researchers describe AnonyMousKIT as a "small software business with a criminal customer base" rather than a typical phishing kit. The platform was still active at the time of the investigation, with ongoing efforts to track its operations and associated storefronts.

phishingbreachvulnerabilityai
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-15409critical

Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter

A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication. It is the shared attack surface where state-sponsored threat actors and financially motivated criminal grou

vulnerability

Four in Five AI Tools Run with No IT Oversight, New Research Finds

Reco report reveals growing shadow AI problem and surge in vulnerability disclosures

breach

CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks

The agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks. The post CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks appeared first on SecurityWeek.

CVE-2026-60004critical

Hackers now exploit critical Gitea flaw in code injection attacks

Attackers are actively exploiting a critical code injection vulnerability (CVE-2026-60004) in the self-hosted Gitea Git service. The flaw allows authenticated users with write access to execute arbitrary shell commands, and with default open registration, unauthenticated attackers can exploit it by creating an account. Gitea has released version 1.27.1 to address the issue, and CISA has ordered U.S. federal agencies to patch within three days due to active exploitation, with reports indicating cryptocurrency mining malware deployment.

mfa

The MFA Identity Trap: When Authentication Creates a False Sense of Security

Organizations are falling into an 'MFA Identity Trap' by conflating identity verification, authentication, and threat detection. This confusion can lead to a false sense of security, where systems successfully authenticate attackers instead of blocking them. A clear distinction between these processes is crucial for effective security.

security

RightCrowd Pass unifies mobile, physical, and biometric credentials

RightCrowd announced RightCrowd Pass, a credentialing solution that issues and manages mobile, physical and biometric access credentials from a single platform. Many large enterprises and universities rely on badge programs-built years ago. As organizations add mobile and biometric credentials, what began as a single access program can fragment into three separate systems, each with its own issuan