{"success":true,"data":{"id":"cloudflare-pages-workers-credential-host","label":"Cloudflare dev-platform abuse — *.pages.dev / *.workers.dev / cloudflare-ipfs.com URL + credential-action lure (Tycoon 2FA / Mamba 2FA hosts)","description":"Email body contains a link to a Cloudflare developer platform host (*.pages.dev, *.workers.dev, cloudflare-ipfs.com, ipfs.dweb.link) combined with credential-action language (sign in, verify account, unlock account, view shared document). Attackers host phishing landing pages on these free platforms because corporate firewalls whitelist Cloudflare domains by default. Cloudflare's own 2026 Threat Report, KnowBe4 (Dec 2025), and CyberPress (Nov 2025) documented 600+ malicious pages.dev subdomains in a single campaign; Tycoon 2FA and Mamba 2FA phishing kits actively use these hosts.","tier":"danger","category":"phishing","isThin":false}}