Fetching from the wire…
Public story · 2026-08-10 · high
The kits reuse near-identical code and lean on mainstream messaging apps to move stolen credentials, per a review of 1,300 samples from 2020-2023.
Why now: The kit analysis is part of the August 10 coverage, examining phishing kits collected through 2023.
A review of 1,300 phishing kits found 284 shipped with zero evasion functionality, per an analysis of kits collected between 2020 and 2023.
That's 21.8% of the sample with no attempt to dodge detection, in a category security teams tend to treat as endlessly adaptive.
The kits also lean on mainstream messaging services to move stolen credentials out, rather than building custom exfiltration infrastructure, per the analysis.
Components inside the kits are close to identical too, kit after kit, per the analysis. The analysis doesn't say whether that overlap comes from shared source kits or copied code circulating after leaks.
Phishing's reputation for constant reinvention doesn't match this sample. If the code and exfiltration channels are really this concentrated, targeting the messaging-app funnel could catch more than chasing kit variants one at a time. Watch whether takedown efforts start going after the messaging-service side instead.
This analysis made the August 10 briefing, examining phishing kits collected through 2023.
Each link below shares sources, entities, or timing with this story.
LangChoiceBench covers 28 projects across seven software areas where Python is a poor default, run against 25 LLMs. Python stays heavily over-selected, recommendation-implementation consistency is low, and smaller open-weight models show stronger bias. Analysis of 9,826 reason...
arXiv 2607.29519 analyzes posts across five research-focused subreddits and finds software engineering grad students systematically outsourcing to LLMs exactly the cognitive effort that builds research skill. The title quote does the work: "You can't outsource the struggle and...
SkillJack found safety detection on poisoned trajectories ran 98.5% but fell to 11.4% on skills extracted from those same trajectories, with 80% of skill-mediated attacks persisting after the original records were deleted. Distillation launders intent. Cleaning your trace stor...
Analysis of 640K AI crawl events shows ChatGPT's crawler at 91% of all AI web crawling activity on B2B sites, specifically targeting pricing pages, case studies, API docs, and technical specs. The implication for builders: AI crawlability is now a first-class concern. Clean ma...
594 upvotes, 127 comments on r/ClaudeAI. Analysis was "surprisingly great" versus expected generic advice. Strong adoption signal for 1M-context beta on personal data — a non-coding use case. r/ClaudeAI
Researchers applied a fixed self-evolution recipe across eight languages and three models (arXiv 2608.10178). Evolved harnesses converge on a shared abstract playbook while each instantiates language-specific machinery; the universal core transfers cleanly, ecosystem-specific...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.