Bleepingcomputer Phishing Threats Exploit Bubble AI App Builder for Microsoft Credential Theft
Article Content
- •Phishers are using Bubble to create deceptive web apps for credential theft.
- •Legitimate URLs from Bubble evade detection by email security systems.
- •The complexity of the generated code complicates automated threat analysis.
Cybercriminals are leveraging the no-code app-building platform Bubble to create and host malicious web applications that target Microsoft accounts. These phishing campaigns utilize legitimate Bubble-hosted URLs, which evade detection by email security solutions, allowing users to unknowingly access fraudulent login pages. The malicious apps often mimic Microsoft login portals and may include additional checks to bypass security measures. Credentials entered on these fake pages are captured by attackers, potentially compromising sensitive Microsoft 365 data. Kaspersky researchers have noted that the complexity of the generated JavaScript and Shadow DOM structures makes it difficult for automated analysis tools to flag these sites as malicious. This tactic is likely to be adopted by phishing-as-a-service platforms, increasing the stealth of such attacks. The situation is evolving, with security experts urging vigilance against this new method of phishing.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Cloudflare in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…