AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes
2026-08-26T14:51:41Z•399a232974b1279fba5c43f71897536ad90c3127c3c272aa402714ea5965f2ef
CVE-2026-60004AI agent securityAI voice impersonationActivation LockApple IDCISA KEVGiteaWhatsApp securitybrowser-in-the-browsercode injectioncredential theftexploited in the wildiPhonemobile phishingopen-source securitypasskeysphishingphishing-as-a-serviceproduction data exposureprompt injectionrecruitment scam
What happened
The feed reports active cyber threats including AnonyMousKIT phishing-as-a-service campaigns using AI voice impersonation and large reseller infrastructure to steal Apple credentials and iPhone passcodes, as well as in-the-wild exploitation of critical Gitea vulnerability CVE-2026-60004. It also covers mobile recruitment phishing, WhatsApp security enhancements, AI-agent governance, prompt injection risks, and broader cybersecurity trends.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 399a232974b1279fba5c43f71897536ad90c3127c3c272aa402714ea5965f2ef
- Enrichment time
- 2026-08-26T14:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.