Post #4027903
2026-07-23 05:27 UTC
One of the ways the security landscape has changed - which I haven't seen discussed - is that URL blocklists seem a lot easier for attackers to evade.
I had a Clickfix incident three days ago. I used a https://app.any.run/ sandbox to replicate that loading the site, which was full of hidden online casino SEO spam, delivered a password stealer.
Reported to Google Safebrowse, Fortigate, Palo Alto, Microsoft.
Today the URL has absolutely 0 flags on Virustotal.
Replies (0)
No replies.