THURSDAY, JUNE 25, 2026 48° E  /  GLOBAL TECH · SUMMARISED SUBSCRIBE
AI, business, devices, policy — global tech, summarised every 30 minutes.
Security · 2h ago

BlueKit phishing kit adds browser-in-the-middle for stealthy credential theft

By Meridian48 News Desk · Summarised from Bleeping Computer ·

The BlueKit phishing-as-a-service platform has evolved with browser-in-the-middle capabilities, allowing real-time interception of login credentials and 2FA tokens. Over 70 new hostnames were identified in the past week, indicating active expansion. The kit targets major platforms like Microsoft 365 and Google Workspace.

Meridian48 take
This upgrade makes BlueKit harder to detect than traditional phishing, as the victim interacts with a real website through a proxy, bypassing many security filters.
Read the full reporting
Bluekit phishing kit adopts browser-in-the-middle for login theft →
Bleeping Computer
phishing-as-a-servicecredential-theft
More security briefs
Go deeper on security
AllAIStartupsBusinessDevicesPolicySecurityDev ToolsPakistan