他们现在在用氛围编码垃圾信息。
They're Vibe-Coding Spam Now

原始链接: https://tedium.co/2026/02/25/vibe-coded-email-spam/

## 垃圾邮件的演变 作者注意到一个令人不安的变化:垃圾邮件的设计越来越精良。过去垃圾邮件丑陋且易于识别,但现在却拥有令人惊讶的审美水平,这得益于人工智能驱动的“氛围编码”——用最少的专业技能创造内容。 这构成了一个重大的安全风险。依赖于糟糕设计的传统垃圾邮件检测方法正在失效,使得恶意行为者更容易制作出令人信服的网络钓鱼尝试。人工智能工具现在允许即使是不熟练的人也能生成复杂的诈骗,并以可观的利润出售恶意软件。 虽然这些“氛围诈骗”可能看起来很完美,但它们通常会有破绽——例如,用电子邮件地址代替姓名称呼收件人,或使用可疑的“发件人”地址。作者建议采取主动措施,如电子邮件混淆和使用别名,以保护自己免受这些日益欺骗性的威胁。最终,关键在于网络诈骗的门槛已经大大降低,需要每个人都提高警惕。

## 氛围编码型垃圾邮件激增 - Hacker News 总结 Hacker News 的讨论强调了一种日益增长的复杂垃圾邮件和诈骗趋势,被称为“氛围编码”。 诈骗者不再从头开始创建电子邮件,而是**复制合法电子邮件并微妙地更改链接**,将受害者引导至欺诈页面——甚至模仿社交媒体链接。 用户报告收到高度可信的钓鱼尝试,例如伪装成法国铁路公司的邮件,只有退订链接未被动过手脚。 这种策略利用了对知名品牌的信任。 对话表达了对日益频繁的数据泄露(个人数据的“氛围编码”)正在助长这些攻击的担忧。 许多评论者正在采取更严格的通信过滤器,例如**仅接受来自已知联系人的来电/消息**或实施广泛的黑名单,预计未来“声誉”或信誉将是未知号码/电子邮件触达个人的必要条件。
相关文章

原文

I have a problem: Unlike most people, I actually read my spam folder on a regular basis. (Often, they’re some of the most interesting emails I get.) I find spam to be intriguing, interesting, and often highlighting some modern trends.

And sometimes, it surfaces something I actually care about that missed my other folders, like an upcoming interview I’m excited to share with all of you.

But one thing about spam that has been true across the board is that it’s ugly. Really, really ugly. Often, what will happen with spam is that they’ll get your email address through questionable means, say a leak of your information in an exploit, and flood your inbox with some of the worst crap you’ve ever seen.

But recently, some of these clearly trash emails have gotten a design upgrade:

spam-screenshot.png
A spam email informing me that my fake cloud storage platform is full.

That is a relatively attractive spam email, trying to sell me on a scam. It is obviously the work of one Claude A. Fakeguy.

It has that swing. Other, less attractive spam emails also have this swing, such as this one:

UglySpam.png
A less attractive email informing me of upcoming video game addiction litigation. How did they know!?!?

But what I think the real tell is that these emails hang together when you have images off, which they did not in the past. This is a problem, because in your spam folder, images are automatically turned off.

Hence why this email warning me that my antivirus plus renewal failed now looks like this:

Warning.png
Oh no, what will I do on my Linux computer that doesn’t support your antivirus program?

This is a funny, if troubling element in the history of spam—and probably a spot of bad news for people who use vibe coding to actually make real things.

freespins.png
The strange thing about spam is that it tells you what the internet’s underbelly is into.

The slop looks more competent than ever

Put simply: Now that the baseline of what makes something well-designed, albeit spartan, has increased, many of the signs we once used to detect a spam message are getting thrown out the window.

Which means that we’re more likely to get hit by spam that tricks us into clicking. And that’s bad news as we attempt to protect ourselves from the crap hiding in our inbox. We’re likely to trust less and accidentally give away more. And untrustworthy figures who don’t know how to code are more likely to throw more crap our way.

This is a point Anthropic itself pointed out in one of its own reports from last summer, about “no-code” ransomware that can be built by people incapable of actually building ransomware without the help of an LLM.

Despite this, these people can create commercial malware programs that they can sell for up to $1,200 a pop.

The security platform Guard.io makes clear that platforms like Lovable are going to enable a new class of criminal:

Just like with “Vibe-coding”, creating scamming schemes these days requires almost no prior technical skills. All a junior scammer needs is an idea and access to a free AI agent. Want to steal credit card details? No problem. Target a company’s employees and steal their Office365 credentials? Easy. A few prompts, and you’re off. The bar has never been lower, and the potential impact has never been more significant. That’s what we call VibeScamming.

And, for people who vibe code, the real problem is that, long-term, their stuff is going to look very untrustworthy because of the specific mix of chrome, color, and emojis that vibe-coded applications specialize in.

The thing that ultimately makes something look human is the addition of actual design and human flair. I encourage you to actually put a little humanness into what you build if you’re going to do it and share it with the world.

How to spot a vibe-coded faker

But for many, it is going to be harder than ever to tell what’s real and what’s fake. Which means you should probably go out of your way to use techniques like email obfuscation and email aliases to protect yourself. (It makes it easier to tell which bread-baking forum violated your trust, for one thing.)

On the plus side, there are still tells. A key one is if they refer to you by not your name, but the name of your email address. Another is the from address, which is often some highly obfuscated bit of junk designed to evade detection.

The one that made me laugh recently was when I got really crappy spam emails on an address that has never gotten them for the first time, promoting traditional spam topics with a Claudecore flair. They seemed random, but were extremely easy to get rid of, because they were all emailed from a bare Firebase domain, meaning that I could remove them with the help of a single filter.

Just because spam emails are more attractive now doesn’t mean the people making them aren’t still extremely stupid.

Spam-Free Links

A quick shout-out to the only tool that makes my inbox bearable in 2026, Simplify Gmail.

Oh good, there’s a new web browser for PowerPC Macs in 2026, and per my pal Action Retro, it’s quite good!

Speaking of inboxes, this story of an AI safety exec letting an AI tool delete her inbox is so darkly funny that I’m surprised it’s real.

--

Find this one an interesting read? Share it with a pal!

Want to actually learn how to code with minimal vibes? Check out our sponsor Scrimba, which mixes video lessons with interactive code windows—and makes it feel downright approachable. Sign up here for a 20% discount.

联系我们 contact @ memedata.com