<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>PhishClean Blog</title>
    <link>https://www.phishclean.com/blog</link>
    <atom:link href="https://www.phishclean.com/blog/rss.xml" rel="self" type="application/rss+xml" />
    <description>Phishing and scam campaigns worth knowing about, browser-security guides and PhishClean product updates.</description>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 12:00:00 GMT</lastBuildDate>
    <item>
      <title>What's new in PhishClean 1.5.0: reported phishing sites blocked, fake virus pages caught</title>
      <link>https://www.phishclean.com/blog/whats-new-phishclean-1-5-0</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/whats-new-phishclean-1-5-0</guid>
      <pubDate>Fri, 09 Oct 2026 12:00:00 GMT</pubDate>
      <description>About 378,000 reported phishing sites blocked for free and checked on your device, a warning on fake virus pages before you call the number, and a fix for plain http:// pages.</description>
    </item>
    <item>
      <title>What's new in PhishClean 1.4.0: breached sites and leaked passwords</title>
      <link>https://www.phishclean.com/blog/whats-new-phishclean-1-4-0</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/whats-new-phishclean-1-4-0</guid>
      <pubDate>Sat, 26 Sep 2026 12:00:00 GMT</pubDate>
      <description>A heads-up when a site you sign in to has had a data breach, and a private check that tells you if the password you type has already leaked. Powered by Have I Been Pwned.</description>
    </item>
    <item>
      <title>Weekly phishing roundup: EvilTokens taken down, Revolut texts, fake Bitrefill checkouts</title>
      <link>https://www.phishclean.com/blog/weekly-phishing-roundup-2026-09-25</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/weekly-phishing-roundup-2026-09-25</guid>
      <pubDate>Fri, 25 Sep 2026 12:00:00 GMT</pubDate>
      <description>Microsoft and UK police take down EvilTokens, Revolut customers get phishing texts days after a breach, fake Bitrefill checkouts turn up in search results, and a Zoom/DocuSign wave hits inboxes.</description>
    </item>
    <item>
      <title>Fake e-Challan messages: how India's traffic-fine scam steals cards, OTPs and UPI PINs</title>
      <link>https://www.phishclean.com/blog/fake-e-challan-scam-india-2026</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/fake-e-challan-scam-india-2026</guid>
      <pubDate>Fri, 25 Sep 2026 12:00:00 GMT</pubDate>
      <description>An SMS says you owe a traffic fine. The link opens a copy of the Parivahan site that only takes cards, or asks you to install "RTO Challan.apk". How the scam works and how to check a challan safely.</description>
    </item>
    <item>
      <title>FBI warns of OAuth consent phishing: the "Allow" button that survives a password reset</title>
      <link>https://www.phishclean.com/blog/fbi-oauth-consent-phishing-warning</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/fbi-oauth-consent-phishing-warning</guid>
      <pubDate>Fri, 25 Sep 2026 12:00:00 GMT</pubDate>
      <description>No fake login page, no stolen password. The victim signs in on the real Google or Microsoft page and clicks Allow, and a malicious app keeps access even after a password change.</description>
    </item>
    <item>
      <title>Invisible characters, real phishing: Microsoft finds ASCII smuggling used to slip past email filters</title>
      <link>https://www.phishclean.com/blog/invisible-unicode-phishing-ascii-smuggling</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/invisible-unicode-phishing-ascii-smuggling</guid>
      <pubDate>Fri, 25 Sep 2026 12:00:00 GMT</pubDate>
      <description>A technique from AI prompt-injection research turned up in a phishing campaign that peaked at 2.37 million messages a day. The words look normal to you, but the filter reads something different.</description>
    </item>
    <item>
      <title>"This is IT, we need to migrate your account": the vishing campaign hitting financial firms</title>
      <link>https://www.phishclean.com/blog/helpdesk-vishing-financial-firms-2026</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/helpdesk-vishing-financial-firms-2026</guid>
      <pubDate>Fri, 25 Sep 2026 12:00:00 GMT</pubDate>
      <description>Callers pose as the IT helpdesk, push an urgent "security migration", and send employees to login portals that capture passwords and MFA codes as they are typed. Ransom demands reach $3 million.</description>
    </item>
    <item>
      <title>What's new in PhishClean 1.3.0: see your protection working</title>
      <link>https://www.phishclean.com/blog/whats-new-phishclean-1-3-0</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/whats-new-phishclean-1-3-0</guid>
      <pubDate>Fri, 25 Sep 2026 12:00:00 GMT</pubDate>
      <description>A pages-checked count on the toolbar, a weekly safety report, a what-to-do-now guide for bad clicks, detection for common Indian scam pages, and rupee pricing.</description>
    </item>
    <item>
      <title>What's new in PhishClean 1.2.0: subscribe without an account</title>
      <link>https://www.phishclean.com/blog/whats-new-phishclean-1-2-0</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/whats-new-phishclean-1-2-0</guid>
      <pubDate>Mon, 21 Sep 2026 12:00:00 GMT</pubDate>
      <description>Pay in two clicks with no account, a one-time heads-up on the day the trial ends, two checks that never expire, and a fix for paid status carrying over to a new account.</description>
    </item>
    <item>
      <title>What's new in PhishClean 1.1.6: a harder-to-fool detection engine</title>
      <link>https://www.phishclean.com/blog/whats-new-phishclean-1-1-6</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/whats-new-phishclean-1-1-6</guid>
      <pubDate>Wed, 15 Jul 2026 12:00:00 GMT</pubDate>
      <description>Lookalike and homograph domain detection, live re-scanning on SPA navigation and DOM changes, deeper secret scanning, and a more accessible warning modal.</description>
    </item>
    <item>
      <title>Ghost phishing: why a clean URL scan no longer means a clean page</title>
      <link>https://www.phishclean.com/blog/ghost-phishing-eviltokens-browser-blind-spot</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/ghost-phishing-eviltokens-browser-blind-spot</guid>
      <pubDate>Tue, 14 Jul 2026 12:00:00 GMT</pubDate>
      <description>The EvilTokens wave ships its page as encrypted code that only decrypts inside your browser, so URL and email scanners see nothing. Why the browser is the real blind spot.</description>
    </item>
    <item>
      <title>Attackers are now phishing your passkey enrollment, not just your password</title>
      <link>https://www.phishclean.com/blog/entra-passkey-enrollment-vishing</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/entra-passkey-enrollment-vishing</guid>
      <pubDate>Sun, 12 Jul 2026 12:00:00 GMT</pubDate>
      <description>Okta warns of a vishing campaign that calls employees, walks them through a fake Microsoft Entra passkey setup, and quietly registers the attacker's own passkey on the real account.</description>
    </item>
    <item>
      <title>24 billion stolen logins: what a record credential dump means for you</title>
      <link>https://www.phishclean.com/blog/24-billion-credential-dump-stuffing</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/24-billion-credential-dump-stuffing</guid>
      <pubDate>Fri, 10 Jul 2026 12:00:00 GMT</pubDate>
      <description>A 24-billion-record credential database built from infostealer logs and enriched with live CVE data was found exposed. Why it fuels credential stuffing - and what actually helps.</description>
    </item>
    <item>
      <title>GitBait: when a trusted GitHub URL hosts a fake bank login</title>
      <link>https://www.phishclean.com/blog/gitbait-github-pages-banking-phishing</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/gitbait-github-pages-banking-phishing</guid>
      <pubDate>Wed, 08 Jul 2026 12:00:00 GMT</pubDate>
      <description>The GitBait campaign abused GitHub Pages to host fake banking portals, borrowing a trusted domain's reputation to steal logins and card details. Why trusted-host phishing works.</description>
    </item>
    <item>
      <title>Surge in OAuth redirect phishing: why it matters</title>
      <link>https://www.phishclean.com/blog/google-oauth-phishing-surge-2026</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/google-oauth-phishing-surge-2026</guid>
      <pubDate>Thu, 18 Jun 2026 12:00:00 GMT</pubDate>
      <description>A look at why OAuth consent and redirect abuse is rising, and how to spot risky authorization flows.</description>
    </item>
    <item>
      <title>Chrome extension malvertising wave: what users should know</title>
      <link>https://www.phishclean.com/blog/chrome-extension-malvertising-wave</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/chrome-extension-malvertising-wave</guid>
      <pubDate>Thu, 18 Jun 2026 12:00:00 GMT</pubDate>
      <description>Extensions injecting ads and redirects can push users into phishing pages; how to audit extensions and reduce risk.</description>
    </item>
    <item>
      <title>MFA fatigue attacks are rising: how to defend</title>
      <link>https://www.phishclean.com/blog/mfa-fatigue-attacks-rise</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/mfa-fatigue-attacks-rise</guid>
      <pubDate>Thu, 18 Jun 2026 12:00:00 GMT</pubDate>
      <description>Understanding MFA fatigue and steps to reduce exposure, including phishing-resistant second factors and browser signals.</description>
    </item>
    <item>
      <title>Supply-chain SMS phishing: attackers leverage messaging channels</title>
      <link>https://www.phishclean.com/blog/supply-chain-sms-phishing</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/supply-chain-sms-phishing</guid>
      <pubDate>Thu, 18 Jun 2026 12:00:00 GMT</pubDate>
      <description>Why supply-chain or provider-abuse phishing via SMS is growing, and what to check in the browser after clicking links.</description>
    </item>
    <item>
      <title>OAuth redirect campaign mitigation: browser and identity controls</title>
      <link>https://www.phishclean.com/blog/oauth-redirect-campaign-mitigation</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/oauth-redirect-campaign-mitigation</guid>
      <pubDate>Thu, 18 Jun 2026 12:00:00 GMT</pubDate>
      <description>A practical mitigation guide for consent settings, redirect review, user education, browser checks, and response steps.</description>
    </item>
    <item>
      <title>European Commission cloud breach shows how one AWS account can spill sensitive data</title>
      <link>https://www.phishclean.com/blog/european-commission-cloud-breach-aws-exposure</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/european-commission-cloud-breach-aws-exposure</guid>
      <pubDate>Mon, 06 Apr 2026 12:00:00 GMT</pubDate>
      <description>A recent europa.eu breach tied to a compromised cloud account is a reminder that public-facing infrastructure can still expose directories, keys, and documents with real downstream risk.</description>
    </item>
    <item>
      <title>CareCloud breach filing shows why an eight-hour healthcare incident still matters</title>
      <link>https://www.phishclean.com/blog/carecloud-patient-data-breach-sec-filing</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/carecloud-patient-data-breach-sec-filing</guid>
      <pubDate>Mon, 06 Apr 2026 12:00:00 GMT</pubDate>
      <description>CareCloud's SEC filing shows why a short-lived healthcare breach can still become material when patient information may have been reachable or exfiltrated.</description>
    </item>
    <item>
      <title>Best affiliate products for cybersecurity bloggers in 2026</title>
      <link>https://www.phishclean.com/blog/best-affiliate-products-for-cybersecurity-bloggers</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/best-affiliate-products-for-cybersecurity-bloggers</guid>
      <pubDate>Mon, 06 Apr 2026 12:00:00 GMT</pubDate>
      <description>What security creators should look for in affiliate products and why narrower browser-security SaaS can be easier to recommend credibly.</description>
    </item>
    <item>
      <title>Best browser security affiliate programs in 2026</title>
      <link>https://www.phishclean.com/blog/best-browser-security-affiliate-programs</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/best-browser-security-affiliate-programs</guid>
      <pubDate>Mon, 06 Apr 2026 12:00:00 GMT</pubDate>
      <description>A practical look at browser-security affiliate programs, what audiences actually care about, and why phishing-focused tools are easier to explain honestly.</description>
    </item>
    <item>
      <title>How to promote affiliate products without losing trust</title>
      <link>https://www.phishclean.com/blog/how-to-promote-affiliate-products-without-losing-trust</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/how-to-promote-affiliate-products-without-losing-trust</guid>
      <pubDate>Mon, 06 Apr 2026 12:00:00 GMT</pubDate>
      <description>How creators can write affiliate content that still feels credible, especially in privacy, security, and technical niches.</description>
    </item>
    <item>
      <title>Microsoft says OAuth redirect abuse is helping phishing links look trustworthy</title>
      <link>https://www.phishclean.com/blog/microsoft-oauth-redirection-phishing-malware</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/microsoft-oauth-redirection-phishing-malware</guid>
      <pubDate>Sat, 21 Mar 2026 12:00:00 GMT</pubDate>
      <description>Microsoft says attackers are abusing legitimate identity-provider redirects to move users from trusted login URLs to phishing pages and malware.</description>
    </item>
    <item>
      <title>FBI warns permit applicants about city and county zoning-fee phishing emails</title>
      <link>https://www.phishclean.com/blog/fbi-zoning-permit-phishing-scam</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/fbi-zoning-permit-phishing-scam</guid>
      <pubDate>Sat, 21 Mar 2026 12:00:00 GMT</pubDate>
      <description>The FBI says criminals are using real permit details and urgent payment lures to make city and county phishing emails feel routine.</description>
    </item>
    <item>
      <title>That purchase order PDF might just be a browser phishing page</title>
      <link>https://www.phishclean.com/blog/purchase-order-pdf-telegram-phishing</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/purchase-order-pdf-telegram-phishing</guid>
      <pubDate>Sat, 21 Mar 2026 12:00:00 GMT</pubDate>
      <description>A fake purchase-order attachment reported this month shows how a browser page can hide inside a so-called PDF and steal business credentials.</description>
    </item>
    <item>
      <title>Fake Google security checks are now installing browser-based phishing apps</title>
      <link>https://www.phishclean.com/blog/fake-google-security-pwa-phishing</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/fake-google-security-pwa-phishing</guid>
      <pubDate>Sat, 21 Mar 2026 12:00:00 GMT</pubDate>
      <description>Researchers say a fake Google security page is abusing PWA installation and browser permissions to steal OTPs, contacts, and more.</description>
    </item>
    <item>
      <title>Fake Google Meet updates are turning a single click into device enrollment</title>
      <link>https://www.phishclean.com/blog/google-meet-update-device-enrollment-phishing</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/google-meet-update-device-enrollment-phishing</guid>
      <pubDate>Sat, 21 Mar 2026 12:00:00 GMT</pubDate>
      <description>A recent report says a fake Meet update page can push users into attacker-controlled device management without starting with a password prompt.</description>
    </item>
    <item>
      <title>Starbucks employee breach shows how phishing against HR portals turns into identity risk</title>
      <link>https://www.phishclean.com/blog/starbucks-phishing-breach-partner-central-employees</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/starbucks-phishing-breach-partner-central-employees</guid>
      <pubDate>Thu, 19 Mar 2026 12:00:00 GMT</pubDate>
      <description>Nearly 900 Starbucks employees were reportedly affected after phishing sites impersonated the company&amp;apos;s HR portal. Here is why HR logins are such a high-value target.</description>
    </item>
    <item>
      <title>The browser has become the most overlooked security risk in everyday life</title>
      <link>https://www.phishclean.com/blog/the-browser-has-become-the-most-overlooked-security-risk-in-everyday-life</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/the-browser-has-become-the-most-overlooked-security-risk-in-everyday-life</guid>
      <pubDate>Tue, 17 Mar 2026 12:00:00 GMT</pubDate>
      <description>Why ordinary users and teams keep getting hurt by browser-level risk, and why the modern web is very good at looking trustworthy while doing something dangerous underneath.</description>
    </item>
    <item>
      <title>A CAPTCHA told me to press Win+R. Is it a virus?</title>
      <link>https://www.phishclean.com/blog/captcha-told-me-to-press-win-r-is-it-a-virus</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/captcha-told-me-to-press-win-r-is-it-a-virus</guid>
      <pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
      <description>Fake verification pages are increasingly telling users to paste commands into Run or PowerShell. Here is why that is dangerous and what to do if you already did it.</description>
    </item>
    <item>
      <title>Why do sites ask you to click Allow notifications?</title>
      <link>https://www.phishclean.com/blog/why-sites-ask-you-to-click-allow-notifications</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/why-sites-ask-you-to-click-allow-notifications</guid>
      <pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
      <description>A lot of scam pages only want one thing from you: notification permission. Here is what happens after that click and how to undo it.</description>
    </item>
    <item>
      <title>I scanned a QR code. Now what?</title>
      <link>https://www.phishclean.com/blog/i-scanned-a-qr-code-now-what</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/i-scanned-a-qr-code-now-what</guid>
      <pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
      <description>A practical response guide for suspicious QR scans, including what matters if you only opened the page, entered a password, or made a payment.</description>
    </item>
    <item>
      <title>Why a phishing site can look safe on desktop but not on phone</title>
      <link>https://www.phishclean.com/blog/why-a-phishing-site-can-look-safe-on-desktop-but-not-phone</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/why-a-phishing-site-can-look-safe-on-desktop-but-not-phone</guid>
      <pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
      <description>Mobile screens hide context attackers want you to miss. Here is why suspicious pages often feel more convincing on phones.</description>
    </item>
    <item>
      <title>Can a browser extension steal my login session?</title>
      <link>https://www.phishclean.com/blog/can-a-browser-extension-steal-my-login-session</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/can-a-browser-extension-steal-my-login-session</guid>
      <pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
      <description>Why extension permissions matter more than most users think, and how session theft risk fits into the broader browser-security picture.</description>
    </item>
    <item>
      <title>Why phishing pages look real now</title>
      <link>https://www.phishclean.com/blog/why-phishing-pages-look-real</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/why-phishing-pages-look-real</guid>
      <pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
      <description>Modern phishing pages are built to feel familiar in the first two seconds. Here is why they work and what still gives them away.</description>
    </item>
    <item>
      <title>How to spot a phishing email that looks legitimate</title>
      <link>https://www.phishclean.com/blog/how-to-spot-phishing-email-that-looks-legit</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/how-to-spot-phishing-email-that-looks-legit</guid>
      <pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
      <description>Polished phishing emails are the dangerous ones. Learn the signs that still matter when a message looks professional.</description>
    </item>
    <item>
      <title>Why browser warnings often come too late</title>
      <link>https://www.phishclean.com/blog/why-browser-warnings-often-come-too-late</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/why-browser-warnings-often-come-too-late</guid>
      <pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
      <description>Why a dangerous page can still look normal before any browser warning appears, and why attackers rely on that delay.</description>
    </item>
    <item>
      <title>What can go wrong on public Wi-Fi even with HTTPS</title>
      <link>https://www.phishclean.com/blog/what-can-go-wrong-on-public-wifi-even-with-https</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/what-can-go-wrong-on-public-wifi-even-with-https</guid>
      <pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
      <description>The lock icon helps, but it does not eliminate every risk on public Wi-Fi. Here is what still matters.</description>
    </item>
    <item>
      <title>How to tell if a Microsoft 365 login page is fake</title>
      <link>https://www.phishclean.com/blog/how-to-tell-if-a-microsoft-365-login-page-is-fake</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/how-to-tell-if-a-microsoft-365-login-page-is-fake</guid>
      <pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
      <description>One stolen Microsoft 365 login can expose an entire workday. Here is what to check before entering your password.</description>
    </item>
    <item>
      <title>How to remove fake virus popups that keep coming back</title>
      <link>https://www.phishclean.com/blog/how-to-remove-fake-virus-popup</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/how-to-remove-fake-virus-popup</guid>
      <pubDate>Fri, 06 Mar 2026 12:00:00 GMT</pubDate>
      <description>Still getting the warning after a virus scan? It is almost always a site allowed to send notifications. Exact steps for Chrome, Edge, Firefox, Safari, Android and iPhone.</description>
    </item>
    <item>
      <title>How to protect elderly parents from online scams</title>
      <link>https://www.phishclean.com/blog/protect-elderly-parents-from-online-scams</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/protect-elderly-parents-from-online-scams</guid>
      <pubDate>Fri, 06 Mar 2026 12:00:00 GMT</pubDate>
      <description>A practical guide to protecting elderly parents from phishing, tech support scams and fake virus popups — without being condescending about it.</description>
    </item>
    <item>
      <title>What to do after a phishing attack — step-by-step damage control</title>
      <link>https://www.phishclean.com/blog/what-to-do-after-phishing-attack</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/what-to-do-after-phishing-attack</guid>
      <pubDate>Mon, 02 Mar 2026 12:00:00 GMT</pubDate>
      <description>You clicked the link. You entered your password. Now what? A step-by-step guide to limiting the damage — from changing passwords to freezing accounts.</description>
    </item>
    <item>
      <title>How to check if a website is safe — 7 things to look for</title>
      <link>https://www.phishclean.com/blog/how-to-check-if-website-is-safe</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/how-to-check-if-website-is-safe</guid>
      <pubDate>Mon, 02 Mar 2026 12:00:00 GMT</pubDate>
      <description>Before you enter your password, check these 7 things. Most phishing pages fail at least two of them — if you know what to look for.</description>
    </item>
    <item>
      <title>Is localStorage safe for tokens? Here's the honest answer.</title>
      <link>https://www.phishclean.com/blog/localstorage-token-security-risks</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/localstorage-token-security-risks</guid>
      <pubDate>Wed, 25 Feb 2026 12:00:00 GMT</pubDate>
      <description>If you're storing JWTs in localStorage, every script on the page can read them. That's not a bug — it's how localStorage was designed. Here's why it matters and what to do instead.</description>
    </item>
    <item>
      <title>What are API key leaks?</title>
      <link>https://www.phishclean.com/blog/what-are-api-key-leaks</link>
      <guid isPermaLink="true">https://www.phishclean.com/blog/what-are-api-key-leaks</guid>
      <pubDate>Tue, 24 Feb 2026 12:00:00 GMT</pubDate>
      <description>API keys are the passwords of the modern web. When they leak, attackers get direct access to your cloud infrastructure, payment systems, and user data. Here's everything you need to know.</description>
    </item>
  </channel>
</rss>
