A journalist tested 5 AI models on social-engineering tasks; some produced terrifyingly convincing, personalized phishing messages using real context.
A journalist received a highly personalized phishing message referencing their specific newsletter topics, research interests, and even a niche project (OpenClaw) — later revealing it was AI-generated. Five AI models were tested on their ability to craft social-engineering attacks. Anthropic's unreleased model 'Mythos' is separately cited as a 'cybersecurity reckoning' for its ability to discover zero-day vulnerabilities, currently restricted to select companies and government agencies. The piece underscores that AI is rapidly lowering the skill floor for sophisticated, targeted cyberattacks.
AI-generated spear-phishing now contextualizes targets with professional-grade accuracy — pulling from newsletters, GitHub profiles, and niche project references. If your product involves user communication, invitations, or OAuth flows, the inbound message your users trust least is now the most dangerous. The threat model for developer tools specifically (Telegram bots, API demos, 'lightweight setups') has materially shifted — attackers are mimicking exactly the kind of outreach developers respond to.
Audit your product's inbound communication surface this week: if users receive emails, Slack messages, or bot invites as part of your onboarding or collab flows, test whether your current phishing warnings or sender-verification steps would catch a message that correctly names their last 3 GitHub repos.
Go to claude.ai and open a new conversation
Tags