Oriental Gudgeon ("CoGUI") is a structured phishing kit built on reusable components, storage artifacts, and API-driven workflows.
Designed for scale and persistence across campaigns.
Detection details inside 👇
Public reporting: https://t.co/pCAmH0iNBB - More on urlscan Pro
right monitor is 20 codex instances. left monitor has situational awareness on autoscroll. center monitor is my word doc mainfesto. two keyboards, one for both hands. left airpod is dwarkesh x eric jang, 3x speed. right airpod tchaikovsky. meta quest 3 overlays my HUD: heart rate, words per minute, blood caffeine content. one assistant hooks me to an iv of chinese peptides, cocktail. the other feeds me kimchi. my unitree robot steps in when my posture slouches. blue light beams down on me in my herman miller chair. efficiency. no wasted movement. no wasted thoughts. think you can keep up with me? good luck. this is just for my morning emails.
New TI report 📷
Chenlun (“Outsider”) is a feature-rich phishing kit using modern web frameworks, verification flows, and anti-bot techniques.
A step up in sophistication across Chinese Phishing-as-a-Service ecosystems.
Full analysis + detections 📷
https://t.co/xCeiZZZ37e
llama.cpp adds MTP for the Qwen3.6 family
This is a significant milestone for the local AI ecosystem. The performance jump with these changes is massive and elevates local inference on commodity hardware further.
Special thanks to Aman Gupta for leading this development!
https://t.co/vjaMwEpIaR
New TI report on urlscan Pro 📷
Flyfish is a lightweight phishing kit built around simple but effective API endpoints.
Despite its simplicity, it’s actively used for large-scale victim interaction and data capture.
Detection patterns included 📷
https://t.co/xCeiZZZ37e
@huggingface The app on https://t.co/HOqQINpsrb seems to throw an exception and not work as a result, including search-as-you-type. How am I supposed to find my models! 😅
I strongly believe there are entire companies right now under heavy AI psychosis and its impossible to have rational conversations about it with them. I can't name any specific people because they include personal friends I deeply respect, but I worry about how this plays out.
I lived through the great MTBF vs MTTR (mean-time-between-failure vs. mean-time-to-recovery) reckoning of infrastructure during the transition to cloud and cloud automation. All those arguments are rearing their ugly heads again but now its... the whole software development industry (maybe the whole world, really).
It's frightening, because the psychosis folks operate under an almost absolute "MTTR is all you need" mentality: "its fine to ship bugs because the agents will fix them so quickly and at a scale humans can't do!" We learned in infrastructure that MTTR is great but you can't yeet resilient systems entirely.
The main issue is I don't even know how to bring this up to people I know personally, because bringing this topic up leads to immediately dismissals like "no no, it has full test coverage" or "bug reports are going down" or something, which just don't paint the whole picture.
We already learned this lesson once in infrastructure: you can automate yourself into a very resilient catastrophe machine. Systems can appear healthy by local metrics while globally becoming incomprehensible. Bug reports can go down while latent risk explodes. Test coverage can rise while semantic understanding falls. Changes happens so fast that nobody notices the underlying architecture decaying.
I worry.
.@invisig0th reflects on the work The Vertex Project has accomplished in the past decade (and where things are heading!)
Read the full post here: https://t.co/4Sekdy2ueG
Last week we hosted a hands-on workshop at @pivot_con in Málaga. Participants learned how to hunt and cluster web-based phishing activity using our urlscan Pro platform. If you did not manage to get in, just send us a message and we'll give you a private tour of the platform!
New report: Darcula (“Magic Cat”) is one of the most active phishing frameworks we’re tracking.
From API-driven infra to socket-based comms and fake shop deployments, this kit continues to evolve rapidly.
Breakdown, detections: https://t.co/jnu2zKf8QL
Full report on urlscan Pro
networking as activity is mostly cope.
e.g. the conference circuit, the warm intros, the moving to sf discussions or whatever, oh & the “grabbing coffee” economy.. all of this is overwhelmingly negative selection esp with vc (lol). the ppl worth knowing are usually too busy doing the thing to be farmable, & the ppl available to be networked w/ are available cuz they have literally nothing better going on.
do the work, then publish it loudly enough that the right ppl can find you w/o you having to chase. one way broadcast > two way schmoozing. this is why x matters a ton now more than ever before.
New urlscan report 🚨
We’re kicking off our Chinese phishing series with a deep dive into the Sailor framework.
A modular kit leveraging client-side storage for session tracking and victim management at scale.
Detection included 👇
https://t.co/pJ00o12FtW
New research drop 🚨
We're diving deep into Chinese-language phishing-as-a-service ecosystems powering large-scale global campaigns. From infrastructure to operations, this series uncovers how these platforms scale and evade detection. Starting May 4th:
https://t.co/mJfli7zYHI