A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar found. “By leveraging a critical flaw – the use of bare relative paths – the investigation unraveled a reseller supply chain of 506 domains and 168 storefront brands active since early 2024. Despite leveraging advanced AI to mim

A new phishing-as-a-service (PhaaS) platform, dubbed AnonyMousKIT, is actively being used to automate the theft of Apple ID credentials, which are necessary to bypass the Activation Lock feature on stolen iPhones. The platform leverages advanced AI voice calls to impersonate Apple Support and trick victims into revealing their device passcodes and other sensitive information.
An investigation into AnonyMousKIT revealed a reseller supply chain comprising 506 domains and 168 distinct storefront brands, which have been operational since early 2024. Researchers uncovered these connections by exploiting a critical flaw in the platform's design: the use of bare relative paths, which inadvertently exposed production logs and operator rosters.
The platform's operation is designed to monetize stolen devices by providing a service for thieves who lack the technical skills to bypass Apple's Activation Lock themselves. This security feature, introduced in iOS 7, links an iPhone to its owner's Apple ID when Find My is enabled, preventing unauthorized use even after a factory reset.
AnonyMousKIT subscribers initiate an attack by entering a stolen device's serial number or IMEI into the platform. The system then retrieves information about the device, including its model and current Find My status. This data is used to craft highly targeted phishing messages, delivered via email, SMS, WhatsApp, recorded calls, or live voice agents.
The phishing attempts are particularly effective because they target recent victims of device theft or loss, exploiting their active search efforts and leveraging accurate hardware data. Victims receive messages claiming their device has been found and asking them to verify their identity to retrieve it.
In calls reviewed by researchers, AI voice agents, often using the persona "Alice Dias, Apple Support," tell victims that someone attempted to unlock their phone at an Apple store, and the store is now holding it for security reasons. The agent follows a predefined script, beginning by confirming device ownership and then requesting the victim's four- or six-digit passcode.
After obtaining the passcode, the agent continues the narrative, claiming a recovery case has been opened and asking if the victim received a security link via text. If not, the agent resends the link and guides the victim through entering the unlock code from it. Once the code is confirmed, the call concludes. The stolen credentials can then be used to remove Activation Lock, allowing the device to be resold.
Researchers recovered 200 call logs and 55 transcripts from the voice agents. Of these, 179 calls were directed to Brazil, incurring a total cost of $19.24. The platform supports five voice-agent personas configured in English, Spanish, and Brazilian Portuguese.
AnonyMousKIT is structured in tiers, with a developer creating and selling the platform, buyers licensing it for their branded storefronts, and operators underneath them dispatching phishing messages. Researchers describe AnonyMousKIT as a "small software business with a criminal customer base" rather than a typical phishing kit. The platform was still active at the time of the investigation, with ongoing efforts to track its operations and associated storefronts.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.