← Back to feed
DFIREmerging1 sourceAug 24, 2026 · 10:47via AboutDFIR

InfoSec News Nuggets – 08/24/2026

Brief

Fake bank websites play dead to evade security scanners

Researchers have documented a phishing technique called Chameleon SEO Poisoning that uses manipulated search rankings and cloaked, typosquatted banking domains to steal credentials while dodging automated security sweeps.

The trick lies in “presentation control”: a visitor who types the domain in directly gets served a dead, offline-looking page, while the same domain flips to a convincing fake bank login screen for anyone who clicked through from a poisoned search result.

Cases jumped 40% in the second quarter of 2026, and the guidance for defenders is to treat referrer spoofing and browser emulation as standard practice when validating a reported URL, since a direct visit alone no longer reveals anything.

Read more on AboutDFIR