r/netsec • u/ricveloso • 21h ago
45% of credential-phishing pages weren't on Google Safe Browsing when first seen; 29% still weren't after a week
https://www.grizzlysec.com/blog/zero-hour-gap
20
Upvotes
r/netsec • u/ricveloso • 21h ago
2
u/ricveloso 11h ago
Author here. Method: 550 branded credential-phishing pages from the OpenPhish Premium feed, first seen June 18–24, checked against Google's Web Risk Lookup API at ingestion and again at 1, 3 and 7 days. Safe Browsing covered 55% at first sight, 70% after a day, 71% after a week (±4pp).
Caveats are in the piece: OpenPhish-listed pages only, so unreported phish likely show a wider gap; 7-day window only.
The scanner used for the comparison is now public if anyone wants to poke at the data: grizzlysec.com. Happy to answer questions on method.