Thebrighterside.News PhishLumos System Detects Phishing Campaigns Before Expert Verification
Article Content
- •PhishLumos detects phishing campaigns 8 days before expert verification.
- •The system uncovered 192,407 additional URLs from 600 initial links, with 92% flagged as malicious.
- •Phishing complaints exceeded 880,000 in 2023, with losses over $12.5 billion.
Researchers at Tokyo Metropolitan University developed PhishLumos, a system that identifies phishing campaigns by mapping domains, IPs, and certificates. In tests, it detected malicious activity an average of 8 days prior to expert verification across 103 phishing campaigns. The system revealed 192,407 additional URLs from 600 starting links, with 92% later flagged as malicious by VirusTotal. Phishing remains a significant threat, with over 880,000 complaints reported to the FBI in 2023, resulting in losses exceeding $12.5 billion. The system addresses the limitations of existing defenses, which often react to individual links rather than the broader campaign. PhishLumos adapts to content-inaccessible cases, where phishing sites may appear benign or unresponsive to automated scanners. This innovation aims to enhance detection and prevention of phishing attacks, particularly affecting vulnerable populations like older adults.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Backdoor.Win32.PcClient!IK in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…