Scammers are now using fake AI tools to trick victims into handing over their ad accounts and multi-factor authentication codes, with one phishing campaign gathering hundreds of victim submissions. They're getting clever with a technique called browser-in-the-browser, creating fake login prompts that look legit and are almost impossible to spot.
Why prompt injection is table stakes — agentic red teaming is the real gap