InfoSec News Nuggets – 08/24/2026
Brief
Fake bank websites play dead to evade security scanners
Researchers have documented a phishing technique called Chameleon SEO Poisoning that uses manipulated search rankings and cloaked, typosquatted banking domains to steal credentials while dodging automated security sweeps.
The trick lies in “presentation control”: a visitor who types the domain in directly gets served a dead, offline-looking page, while the same domain flips to a convincing fake bank login screen for anyone who clicked through from a poisoned search result.
Cases jumped 40% in the second quarter of 2026, and the guidance for defenders is to treat referrer spoofing and browser emulation as standard practice when validating a reported URL, since a direct visit alone no longer reveals anything.
