{
  "id": 12696721,
  "title": "Browser-in-browser attacks use fake Meta Muse Ad lure to steal credentials",
  "url": "https://urgent.news/2026/10/07/browser-in-browser-attacks-use-fake-meta-muse-ad-lure-to-steal-12696721",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-07T19:33:00.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/research/2026/10/07/browser-in-browser-attacks-use-fake-meta-muse-ad-lure-to-steal-credentials/5301505"
  },
  "original_language": "en",
  "account": "A phishing campaign targeting advertising professionals by impersonating popular AI platforms Gemini, Claude, ChatGPT, Perplexity, and Manus has added a fake Meta Muse Ads product to its tactics. Meta unveiled Muse on September 8, and just eight days later, a convincing website for Muse Ads emerged online. The operators behind the scam quickly adapted the platform to a new brand, turning a timely announcement into a credible reason for people to act. The new Muse Ads page served as a lure for browser-in-the-browser (BitB) attacks aimed at stealing advertising credentials, payment methods, and client accounts from agency staff, media buyers, and manager-account administrators. The BitB technique involves creating a fake login window inside a legitimate one, with a convincing address bar, title, and URL. When the victim clicks the \"connect\" button, it opens an overlay window stealing credentials while the real browser stays on the phishing domain. The campaign has reportedly observed hundreds of victim submissions over a month, with each ad product having its own page and a \"connect\" button. The phishing kit supports Google, Meta, TikTok, and Okta workflows, adapting to the victim's browser and operating system. The operators have exposed older source code through misconfigured public GitHub repositories, linking the campaign to a larger operation. To combat the threat, security teams should maintain a baseline of trusted domains, verify real browser addresses, and monitor similar behavior across different sites.",
  "summary": "Wiley fisherfolk spin up a new page just days after Meta's AI agent launch",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register Science",
        "title": "Browser-in-browser attacks use fake Meta Muse Ad lure to steal credentials",
        "url": "https://urgent.news/2026/10/07/browser-in-browser-attacks-use-fake-meta-muse-ad-lure-to-steal",
        "published": "2026-10-07T19:33:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}