- Advertisement -
- Okta warns Genai tool V0.dev is operated to build phishing sites
- The malignant sites are organized on Vercel infrastructure to look more legitimate
- AI -Tools also often quote false URLs, which means that unsuspecting users run a risk of attacks
New Okta -Research has revealed how threat actors Vercel’s V0.dev use to build realistically phishing Sites that simulate legitimate registration pages, where researchers successfully reproduce the alleged technology to prove its feasibility.
V0.Dev enables users to make web interfaces of simple, natural language prompts, of which researchers say it is worrying, because it has been proven that technology is now lowering the technical barrier for phishing attacks and other types of cyber crime.
Although Vercel and Okta have worked together to limit access to famous sites, many claim that there is little that can be done to prevent such attacks now AI Tools have become so widespread.
Genai now creates phishing sites
Okta thought that the fake phishing sites occur by the company logos and other assets to reduce detection by unsuspecting victims, where the sites on Vercel’s infrastructure seem more legitimate. Microsoft 365 and fake crypto sites were among the most popular.
The Source Availability of V0.Dev clones and guides on Github has also broadened access to these possibilities for less experienced developers and attackers.
OKTA recommends that all users set multi-factor authentication on supported accounts, binding authenticators to original domains via tools such as Okta FastPass to ensure that fake sites do not gain access to your references.
“Organizations can no longer rely on learning users how they can identify suspicious phishing sites based on imperfect imitation of legitimate services,” the researchers from OKTA noted.
Companies must also update their cyber security training programs to tackle risks of phishing attacks and social engineering generated by AI.
The news comes soon after another report revealed around a third of Genai chatbot Answers with login -urls were incorrect, whereby attackers register false domains that are cited by tools such as Chatgpt to set up their own phishing campaigns.
Maybe you like it too
- Advertisement -