Agent Tripwire: Detecting Misbehaving AI Agents at Runtime

Agent Tripwire replaces attack classification with runtime invariants: inert tools, credentials, resources and cross-agent markers that no valid execution should touch. A trip triggers containment before the agent can produce a real side effect.

Device Code Phishing Evasion Techniques

Device-code phishing campaigns are combining CAPTCHA gates, multi-step SaaS lure chains, encrypted blob-page delivery and source-level text obfuscation to evade automated scanners and reputation checks.

Device Code-based OAuth Phishing

An active phishing campaign abuses Microsoft’s legitimate device-code OAuth flow to capture application tokens instead of passwords. The pages combine trusted sign-in screens with obfuscation, developer-tool detection and debugger traps.

IOCs for tech support scam activity

A tech-support scam targeting Japanese speakers combines encrypted JavaScript with browser APIs designed to contain victims, including full-screen locks, keyboard hijacking, resource exhaustion and window re-spawning.

IOCs for phishing pages using blob URLs

Several active phishing campaigns use blob URLs to deliver their final pages. By assembling malicious content in browser memory at runtime, these pages can evade network-based analysis.

IOCs for phishing campaign using BitM pages

Tracking an active browser-in-the-middle phishing campaign that impersonates Meta and Facebook. The campaign uses copyright-infringement lures and redirect chains to send targets to BitM pages.