The age of the static blocklist as a primary phishing defense is ending. Driven by AI, attackers are now creating disposable phishing infrastructure so quickly that traditional lists of known-bad domains and IPs are perpetually behind, according to a recent analysis highlighted by BleepingComputer.

Security firm Push Security argues that the core issue is a fundamental mismatch in speed and strategy. AI toolkits allow threat actors to generate unique domains, rotate cloud hosts, and alter page content in real-time, easily outpacing the update cycles of conventional threat intelligence feeds. This has broken the "identify-and-block" model that email gateways and web proxies have relied on for years.

The proposed solution is a decisive shift from monitoring infrastructure to monitoring behavior. Instead of asking if a domain is malicious, effective defense must analyze what the browser is being instructed to do. This means real-time detection of malicious techniques—such as fake login forms, credential harvesting scripts, or abnormal data exfiltration—at the point of execution: the user's browser.

Implementing this approach carries operational weight. It requires deep integration with existing security tools like EDR and SASE platforms, as well as careful tuning to minimize false positives that disrupt productivity. For IT and security leaders, the immediate action is to begin a phased adoption of these behavioral systems, prioritizing endpoint telemetry while relegating blocklists to a low-priority, supplementary role at best.

This move underscores a broader industry recognition that perimeter defenses alone cannot withstand AI-accelerated threat generation. As phishing becomes more automated and ephemeral, the baseline for enterprise security is shifting toward identifying malicious intent through observed behavior, not historical indicators.


根據近期BleepingComputer報導的一項分析指出,以靜態封鎖列表作為主要網絡釣魚防禦手段的時代正告終。在人工智能驅動下,攻擊者如今能以極快速度建立一次性釣魚基礎設施,導致傳統已知惡意網域與IP位址清單永遠滯後於實際威脅。

網絡安全公司Push Security認為核心問題在於速度與策略的根本性錯配。人工智能工具套件使威脅行為者能夠生成獨立網域、輪換雲端主機,並即時修改網頁內容,輕鬆超越傳統威脅情報源的更新週期。這種模式已瓦解電子郵件閘道與網頁代理伺服器多年依賴的「識別及封鎖」機制。

提出的解決方案是從監控基礎設施轉向監控行為模式的決定性轉變。有效的防禦措施不再是問「該網域是否惡意」,而是必須分析瀏覽器被指示執行的操作。這意味著需在執行層面——即用戶的瀏覽器中——即時偵測惡意技術,例如偽造登入表單、憑證蒐集腳本或異常數據外傳行為。

落實此方案需承擔營運成本。這要求與現有安全工具如EDR及SASE平台進行深度整合,並仔細調整以將妨礙生產力的誤報率降至最低。對資訊科技與安全主管而言,當務之急是開始分階段採用這些行為偵測系統,優先發展端點遙測技術,並將封鎖列表的作用降至次要補充層級。

此舉反映業界更廣泛的認知:單憑邊界防禦已無法抵禦人工智能加速生成的威脅。隨著網絡釣魚攻擊日益自動化且短暫,企業安全基準正從歷史指標轉向透過觀察行為來識別惡意意圖。

新聞來源 / Original News Source