AnalysisCybersecurityJuly 20, 2026

Exposed server reveals AI-assisted phishing toolkit behind WebDAV campaign

Rapid7 discovered an exposed server containing 1,048 files from an active phishing operation targeting Windows users in Mexico via WebDAV. The toolkit abused CVE-2025-33053 (CVSS 8.8) to bypass SmartScreen, with development notes and live delivery logs revealing the operator used generative AI to build and document the attacks.

1 source

More stories today

Open the live feed