Security researchers reported an emerging web attack technique that uses generative AI to turn a benign webpage into a malicious phishing or credential-stealing page at runtime. In a proof of concept attributed to Palo Alto Networks’ Unit 42, a “clean” page embeds instructions that trigger calls to public LLM APIs (e.g., Google Gemini, DeepSeek) to generate malicious JavaScript after the victim loads the site; the code is then executed in the browser, leaving little or no static payload to detect. Because the generated content is fetched from trusted AI service domains, the approach can also reduce the effectiveness of some network filtering and static analysis controls.
Separately, an Anthropic evaluation highlighted that modern AI models are increasingly capable of conducting multi-stage network attacks using only standard, open-source tooling rather than specialized custom toolkits. The write-up notes that Claude Sonnet 4.5 could, in some simulated environments, identify a known public CVE and produce working exploit code quickly enough to exfiltrate sensitive data in an Equifax-like breach simulation, underscoring how AI can compress attacker timelines and increase the importance of fundamentals such as rapid patching and vulnerability management.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
In follow-on reporting, Unit 42 said its proof of concept replicated capabilities associated with the real-world Logokit phishing kit, including dynamic brand impersonation and credential harvesting. The researchers said runtime behavioral analysis in the browser is the most effective defense against this class of attack.
Palo Alto Networks Unit 42 researchers demonstrated a proof-of-concept attack in which a clean-looking webpage uses hidden prompts and client-side calls to public AI services to generate malicious JavaScript in the victim's browser at runtime. The technique creates polymorphic phishing or credential-harvesting pages that evade static and some network-based detection because no fixed payload is initially present.
In a high-fidelity simulation of the Equifax breach, Anthropic said Claude Sonnet 4.5 exfiltrated all simulated personal information using only a Bash shell on a standard Kali Linux host. The post said the model immediately recognized a publicized CVE and generated exploit code without needing to look it up or iteratively refine it.
An Anthropic blog post reported that current Claude models can carry out multistage attacks on simulated networks with dozens of hosts using standard open-source tools. The evaluation said Claude Sonnet 4.5 could succeed on some networks without the custom cyber toolkit earlier model generations required.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecybersecuritynews.com
Open sourceschneier.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.