{
  "id": 12694418,
  "title": "Browser-in-browser attacks use fake Meta Muse Ad lure to steal credentials",
  "url": "https://urgent.news/2026/10/07/browser-in-browser-attacks-use-fake-meta-muse-ad-lure-to-steal",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-07T19:33:00.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/research/2026/10/07/browser-in-browser-attacks-use-fake-meta-muse-ad-lure-to-steal-credentials/5301505"
  },
  "original_language": "en",
  "account": "A phishing campaign targeting advertising managers is using a fake Meta Muse Ads lure to steal credentials and multi-factor authentication (MFA) codes, just eight days after Meta launched its personal AI agent. The campaign has been identified by security researchers at Island, who discovered a convincing website called museads.ai for a product called Muse Ads. The operators have adapted the platform, created to lure users into browser-in-the-browser (BitB) attacks, into a new brand in just minutes. Each fake product page has its own \"connect\" button, which opens a fake browser to steal credentials when users type them in. The BitB technique involves building a fake login window inside a legitimate one, and the fake window looks identical to the real thing. The scam has been successful, with hundreds of victim submissions reported over a month, and the campaign is still ongoing. The operators use the same platform across many similar sites, estimating the campaign-wide volume to be substantially higher. Victims may face loss of access to advertising accounts, unauthorized ad spend, and exposure of linked client accounts.",
  "summary": "Wiley fisherfolk spin up a new page just days after Meta's AI agent launch",
  "key_points": [
    "Fake Meta Muse Ads lure used in phishing campaign",
    "Browser-in-the-browser technique steals credentials",
    "Campaign active for over a month, ongoing"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Browser-in-browser attacks use fake Meta Muse Ad lure to steal credentials",
        "url": "https://urgent.news/2026/10/07/browser-in-browser-attacks-use-fake-meta-muse-ad-lure-to-steal-12696721",
        "published": "2026-10-07T19:33:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}