⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

October 6, 2026

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes Ravie LakshmananOct 06, 2026Phishing / Artificial Intelligence Cybersecurity researchers have disclosed details of a "human-operated phishing platform" that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. The products, which claim to offer campaign optimization, spend audits, and business-account connections, are designed with one goal in mind: to capture credentials and multi-factor authentication (MFA) codes via spoofed login windows using the browser-in-the-browser (BitB) trick. "Each product was built around the same action: Connect," Island researchers Oleg Zaytsev and Ofek Ronen said in a report shared with The Hacker News. "Clicking it opened a browser drawn inside the…

CVEs: CVE-2026-88772