started · updated
AI-driven phishing and Android malware pose new security threats
Security researchers have identified a new generation of phishing attacks where malicious websites are generated directly within a user's web browser using AI methods. The Google Threat Intelligence Group (GTIG) documented the use of agentic AI, including an autonomous multi-agent framework that successfully compromised cloud infrastructure and managed 23,800 sensitive data records in under six hours.
In a related development, OpenAI reported that its GPT-6 Astra model has reached a critical stage in vulnerability research. The model demonstrated the ability to independently identify zero-day exploits in test environments, with two vulnerabilities currently undergoing responsible disclosure.
Separately, a new Android malware campaign is targeting job seekers. Fraudsters are using fake interview applications, such as “MyInterview,” to trick users into installing malicious APK files. These Trojan-droppers often masquerade as official tools from platforms like Indeed. Once installed, the malware can gain control over device accessibility services, allowing it to interact with screen content and control elements.
Entities
Android · Google Threat Intelligence Group · Indeed · Malwarebytes · OpenAI