AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes

2026-08-26T14:51:41Z399a232974b1279fba5c43f71897536ad90c3127c3c272aa402714ea5965f2ef
CVE-2026-60004AI agent securityAI voice impersonationActivation LockApple IDCISA KEVGiteaWhatsApp securitybrowser-in-the-browsercode injectioncredential theftexploited in the wildiPhonemobile phishingopen-source securitypasskeysphishingphishing-as-a-serviceproduction data exposureprompt injectionrecruitment scam

What happened

The feed reports active cyber threats including AnonyMousKIT phishing-as-a-service campaigns using AI voice impersonation and large reseller infrastructure to steal Apple credentials and iPhone passcodes, as well as in-the-wild exploitation of critical Gitea vulnerability CVE-2026-60004. It also covers mobile recruitment phishing, WhatsApp security enhancements, AI-agent governance, prompt injection risks, and broader cybersecurity trends.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
399a232974b1279fba5c43f71897536ad90c3127c3c272aa402714ea5965f2ef
Enrichment time
2026-08-26T14:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.