Cybersecurity Reach Foundation

CSRF Research

Investigations & Reports

Long-form investigative reports and original research on scams, vulnerabilities, and emerging threats — so you know what's out there and how to stay protected.

Latest

· Higor Silva

The Fake Nike Careers Site That Tried to Steal Facebook Logins

A convincing Nike job-site clone used a fake Facebook sign-in to target people looking for work.

Read the full report
The Fake Nike Careers Site That Tried to Steal Facebook Logins

All investigations

It Looked Like Zillow. It Wasn't: Inside the zillowofficial[.]com Investment Scam

· Higor Silva

It Looked Like Zillow. It Wasn't: Inside the zillowofficial[.]com Investment Scam

A passive OSINT investigation found that zillowofficial[.]com impersonated Zillow while presenting an investment-style platform and sharing a technical structure with similar domains.

The Government Health-Card Email That Looked Safe to Scanners

· Faisal Hossain

The Government Health-Card Email That Looked Safe to Scanners

A fake Government of Canada health-card email hid its scam page behind a fake security check, sending scanners and researchers to the real canada.ca.

Port 445 Attacks from Three Indonesian IPs: Findings and Analysis

· Narek Grigoryan

Port 445 Attacks from Three Indonesian IPs: Findings and Analysis

A T-Pot honeypot logged three Indonesian IP addresses scanning port 445 roughly 80,000 times; OSINT review found residential-proxy signals and exposed MikroTik infrastructure.

IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwner: Inside the New Shai-Hulud npm Worm

· Cybersecurity Reach Foundation

IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwner: Inside the New Shai-Hulud npm Worm

A report on a Shai-Hulud npm worm variant that targeted the TanStack ecosystem, harvested credentials, spread through developer environments, and planted destructive persistence.

OpenClaw Risk Report: High Risk

· Seva Karonis

OpenClaw Risk Report: High Risk

A review of OpenClaw's autonomous capabilities, local-machine access, reported issues, prompt-injection exposure, and safer deployment practices.

A Business's Guide to Agentic AI Adoption

· Seva Karonis

A Business's Guide to Agentic AI Adoption

A beginner-friendly guide to adopting agentic AI responsibly, including safe use, onboarding, permission boundaries, and tool evaluation.

L.A.Y.E.R.S. OPSEC Framework

· Cybersecurity Reach Foundation

L.A.Y.E.R.S. OPSEC Framework

A practical six-step OPSEC guide for investigators, researchers, and anyone who needs to reduce exposure while working online.

Fake Meetup Messages Are Stealing Bank Details From Event Organizers

· Cybersecurity Reach Foundation

Fake Meetup Messages Are Stealing Bank Details From Event Organizers

Messages sent through real Meetup accounts used a look-alike link and a fake security screen to lead event organizers to a page asking for bank and card details.

ALERT: SpiderFoot Scam Resurfaced on spiderrfoot[.]com

· Cybersecurity Reach Foundation

ALERT: SpiderFoot Scam Resurfaced on spiderrfoot[.]com

A deceptive SpiderFoot distribution scheme resurfaced on spiderrfoot[.]com, showing how users can be misled when an open-source project has no official website.

Rixav[.]sbs: A Crypto Wallet Phishing Site

· Pammi Balani

Rixav[.]sbs: A Crypto Wallet Phishing Site

rixav[.]sbs impersonates a wallet recovery service to trick users into entering their seed phrases and private keys. This report documents how the scam works, what the site does with your credentials, and why any wallet that touched it should be considered compromised.

Evofince: Fake Licenses, Template Infrastructure, and a Phantom Crypto Exchange

· Tenzin Phuntsok

Evofince: Fake Licenses, Template Infrastructure, and a Phantom Crypto Exchange

This investigation analyzes evofince[.]com, a cryptocurrency trading platform that presents itself as a high-volume digital asset exchange. Despite claims of regulatory licensing and years of operational history, domain records show the website was only registered in January 2026.

FineretCreditUnion.com: Credit Union Using Recycled Scam Infrastructure

· Matthew Sweet

FineretCreditUnion.com: Credit Union Using Recycled Scam Infrastructure

A website claiming to be a legitimate credit union appears to be part of a template-based financial scam network designed to collect personal information and solicit fraudulent loan payments.

Spiderfoot.org: Google Search Mislabels an Unofficial SpiderFoot Site

· Pammi Balani

Spiderfoot.org: Google Search Mislabels an Unofficial SpiderFoot Site

An unofficial website appearing in search results for the SpiderFoot OSINT tool may be misleading users into downloading software through untrusted channels. Despite the site itself stating it is not affiliated with the official project, search engine AI summaries identify it as the legitimate source