Dual-Engine PhaaS Hunting: Integrating urlquery.net into the Pipeline
TL;DR: We integrated urlquery.net as a second web scanning engine alongside urlscan.io in our MCP-powered phishing infrastructure pipeline. The re-run of
Hugging Face says hosted frontier models blocked its forensic prompts during an AI-driven intrusion. A locally hosted GLM 5.2 helped analyse more than 17,000 events without the evidence or credentials leaving its environment.
read post →TL;DR: We integrated urlquery.net as a second web scanning engine alongside urlscan.io in our MCP-powered phishing infrastructure pipeline. The re-run of
Date: July 8, 2026 Subject: Analysis of the Accenture 35GB data breach claim Classification: Open-source intelligence report Executive Summary A threat actor using the alias
TL;DR: PhaaS domains churn faster than IOC lists can ship. We built a self-hosted MCP server that runs an OSINT pipeline from a source
Inside Mirage2FA — Reverse-Engineering a Two-Year M365 Phishing Operation Adverse Trace OSINT · 2026-06-29 · TLP:CLEAR Campaign: AT-IR-2026-MIRAGE2FA · Activity: Jun 2024
Bluekit and the AI Impersonators: A Phishing Kit Hunt That Uncovered a Fraud Empire 26 June 2026 · FindEvil — dAIffed / Adverse Trace · Case Refs: BLUEKIT-PHA-2026-
Original inspiration for this from https://abnormal.ai/blog/eviltokens-oauth-device-codes-bec-operations EvilTokens Is Still Live: Three Months On, the PhaaS Platform Has
1. Executive summary Okta's Enterprise AI Index, drawing on anonymised sign-on data from over 20,000 organisations (June 2022–June 2026)
1. Executive summary Pillar Security researchers demonstrated sandbox escapes across four widely used AI coding agents — Cursor, OpenAI Codex CLI, Google Gemini CLI, and
1. Executive summary JADEPUFFER, an actor attributed by Sysdig to an autonomous LLM-driven AI agent (no MITRE ATT&CK profile exists for
1. Executive summary CVE-2026-53359 ("Januscape") is a HIGH-severity (CVSS 8.8) use-after-free vulnerability in the Linux KVM
1. Executive summary A critical code injection vulnerability (CVE-2026-6875, CVSS 9.5) in the ServiceNow AI Platform is being actively exploited in