Close Menu
TechurzTechurz
    What's Hot

    This young startup is taking on a fragrance industry that hasn’t changed in a almost half century

    May 21, 2026

    Maka Kids is redefining kids’ screen time with a streaming app optimized for well-being, not engagement

    May 21, 2026

    Beauty booking startup Fresha hits $1 billion valuation with KKR backing

    May 21, 2026
    Facebook X (Twitter) Instagram
    Tech Pulse
    • This young startup is taking on a fragrance industry that hasn’t changed in a almost half century
    • Maka Kids is redefining kids’ screen time with a streaming app optimized for well-being, not engagement
    • Beauty booking startup Fresha hits $1 billion valuation with KKR backing
    • General Catalyst just led a $63M bet on India’s travel payments market
    • Clouted wants to take the guesswork out of making short videos go viral
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    TechurzTechurz
    • Home
    • Tech Pulse
    • AI Systems
    • Cyber Reality
    • Future Tech
    • Disruption Lab
    • Signals
    TechurzTechurz
    Home - Security - LLMs are guessing login URLs, and it’s a cybersecurity time bomb
    Security

    LLMs are guessing login URLs, and it’s a cybersecurity time bomb

    TechurzBy TechurzJuly 1, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Phishing-Angriff
    Share
    Facebook Twitter LinkedIn Pinterest Email


    “This creates a perfect storm for cybercriminals,” said J Stephen Kowski, Field CTO at SlashNext. “When AI models hallucinate URLs pointing to unregistered domains, attackers can simply register those exact domains and wait for victims to arrive.” He likens it to giving attackers a roadmap to future victims. “A single malicious link recommended can compromise thousands of people who would normally be more cautious.”

    The findings from Netcraft research are particularly concerning as National brands, mainly in finance and fintech, were found among the hardest hit. Credit unions, regional banks, and mid-sized platforms fared worse than global giants. Smaller brands, which are less likely to appear in LLM training data, were highly hallucinated.

    “LLMs don’t retrieve information, they generate it,” said Nicole Carignan, Field CISO at Darktrace. “And when users treat those outputs as fact, it opens the door for massive exploitation.” She pointed to an underlying structural flaw: models are designed to be helpful, not accurate, and unless AI responses are grounded in validated data, they will continue to invent URLs, often with dangerous consequences.

    Researchers pointed out that registering all the hallucinated domains in advance, a seemingly viable solution, will not work as the variations are infinite and LLMs are always going to invent new ones, leading to slopsquatting attacks.

    bomb cybersecurity guessing LLMs login time URLs
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThis home NAS with 32TB, 4K HDMI, and AI photo sorting sounds too wild to ignore
    Next Article A Pro-Russia Disinformation Campaign Is Using Free AI Tools to Fuel a ‘Content Explosion’
    Techurz
    • Website

    Related Posts

    Opinion

    Maka Kids is redefining kids’ screen time with a streaming app optimized for well-being, not engagement

    May 21, 2026
    Opinion

    The Minneapolis tech community holds strong during ‘tense and difficult time’

    February 3, 2026
    Opinion

    VCs abandon old rules for a ‘funky time’ of investing in AI startups

    November 14, 2025
    Add A Comment
    Top Posts

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    AI is becoming introspective – and that ‘should be monitored carefully,’ warns Anthropic

    November 3, 202512 Views
    Stay In Touch
    • YouTube
    • WhatsApp
    • Twitter
    • Pinterest
    • LinkedIn
    Latest Reviews

    Techurz is a future-first technology publication covering AI systems, cyber reality, future tech, disruption, and digital signals — written today, searched tomorrow.

    Company:
    • About Us
    • Contact Us
    • Our Authors / Editorial Team
    • Write For Us
    • Advertise
    Policy:
    • Editorial Policy
    • Privacy Policy
    • Terms and Conditions
    • Affiliate Disclosure
    • Cookie Policy
    • Disclaimer
    • DMCA

    Join the Techurz Brief

    The future does not arrive suddenly.
    Get sharp weekly signals on the technologies, risks, tools, and shifts that matter before they become obvious.

    Type above and press Enter to search. Press Esc to cancel.