Today we are joined by Ensar Seker, VP of Research and CISO at SOCRadar, discussing their work on "Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain." An investigation into AnonyMousKIT reveals an AI-powered Phishing-as-a-Service platform designed to steal Apple credentials and disable Activation Lock on stolen devices.
The platform uses email, SMS, WhatsApp, and AI-driven voice calls to impersonate Apple Support, with researchers uncovering a broader ecosystem spanning 506 domains, 168 storefront brands, and 30 backend installations. Despite its sophisticated social-engineering capabilities, basic coding flaws exposed extensive operational logs and revealed the shared infrastructure, developer activity, and reseller network behind the criminal operation. Research Saturday
Today we are joined by Ensar Seker, VP of Research and CISO at SOCRadar, discussing their work on "Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain." An investigation into AnonyMousKIT reveals an AI-powered Phishing-as-a-Service platform designed to steal Apple credentials and disable Activation Lock on stolen devices.
The platform uses email, SMS, WhatsApp, and AI-driven voice calls to impersonate Apple Support, with researchers uncovering a broader ecosystem spanning 506 domains, 168 storefront brands, and 30 backend installations. Despite its sophisticated social-engineering capabilities, basic coding flaws exposed extensive operational logs and revealed the shared infrastructure, developer activity, and reseller network behind the criminal operation. Research Saturday
Cybersecurity News

Week that Was

CyberWire Daily

Daily Briefing

CyberWire Daily

Caveat

Daily Briefing

Caveat

Hacking Humans

AI Security Brief
In traditional IT, isolating a compromised endpoint can stop an attack. In operational technology (OT) environments, that same action could disrupt control of a pipeline, cause a rupture, or trigger environmental damage.
That’s why adopting AI in critical infrastructure requires a fundamentally different security approach. Drawing on more than 25 years of experience across energy, pipelines, aerospace, and defense, Jason Cradit, CTO and CISO at Everline, explains how security leaders can move beyond blanket restrictions and establish practical AI governance and guardrails. 
CyberWire Daily

Business

Daily Briefing