RatHat's malware console now feeds stolen texts to Google's Gemini to estimate each victim's bank balance and rank who to rob first, security firm Cleafy says. Cleafy has traced nearly 100 deployments since April 2026 and found nothing that moves money.
Reality
- Evidence55
- Adoption25
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
Malwarebytes says the fake Avast renewal page it found aimed at Belgian users was noticeably more polished than most scam sites, with clean French copy, an Active status badge and a form that asks only for a name, an email address and a phone number.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence60
Microsoft says the phishing-as-a-service platform reached more than 12,000 inboxes at over 10,000 organizations in seven months by abusing a legitimate OAuth flow, and its Digital Crimes Unit has now disrupted the infrastructure behind the service.
Reality
- Evidence58
- Adoption62
- Hype gap+20
- Incentives76
- Confidence57
Seemant Sehgal, whose firm sells continuous penetration testing, says AI agents have cut the skill needed to run a full intrusion campaign. His evidence is two August 2025 incidents and one unmeasured claim about speed.
Reality
- Evidence26
- Adoption22
- Hype gap+44
- Incentives88
- Confidence58
Rapid7 recovered an exposed server running an active vishing operation. Alongside the phishing kit sat the operator's development trail, including a custom jailbreak written after one model pushed back.
Reality
- Evidence62
- Adoption58
- Hype gap+12
- Incentives68
- Confidence60