{"success":true,"data":{"id":"runtime-llm-page-loader","label":"AI-page-builder platform (Gamma/Framer/Tome) abused to host credential-harvest phishing lure","description":"AI page-builder platform (Gamma, Framer, Tome, etc.) abused to host a credential-harvest phishing lure. In 2026, phishing operators use no-code AI presentation and website builders to create polished phishing pages that share the hosting platform's HTTPS certificate and CDN reputation. The signal fires when: (1) a link to a known AI-page-builder free hosting domain (*.gamma.app, *.framer.site, *.framer.app, *.tome.app, *.beautiful.ai, *.my.canva.site) appears AND (2) a credential/account-action narrative is present (verify, sign in, suspended, restore access) AND (3) sender is NOT from the legitimate service domain. Source: GC1 R12 council #7; Proofpoint AI-lure abuse 2026; APWG no-code platform abuse Q2 2026.","tier":"warning","category":"other","isThin":false}}