Tycoon2FA Phishing-as-a-Service Platform Persists Following Takedown

2026-03-22T19:23:34Zb68cd363dcb8acfbf3fdfa4a7f7a421bfb199b54bff9f4f0d2476ecdcb11a409
ai-securitycharlotte-aicritical-vulnsfalcon-aidrhealthcare-securitymacos-sensornational-securitynetwork-visibilitynext-gen-siemnvidia-nemopatch-tuesdayphishingphishing-as-a-servicestealersupply-chain-compromisetrivy-actiontycoon2favulnerabilitiesxiot

What happened

CrowdStrike blog roundup (Mar 6–20, 2026) covering multiple security topics: persistence of the Tycoon2FA phishing-as-a-service platform after takedown attempts; a supply-chain compromise of the trivy-action that escalated from scanner to stealer; guidance for securing in-house AI agents using CrowdStrike Falcon AIDR and NVIDIA NeMo Guardrails; expanded Falcon for XIoT offerings (including healthcare-focused protections); enhancements to Falcon macOS sensor for improved network visibility; rollout of Falcon Next‑Gen SIEM with sensor-native log collection; and CrowdStrike’s March 2026 Patch T u

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
crowdstrike_blog
Record identifier
b68cd363dcb8acfbf3fdfa4a7f7a421bfb199b54bff9f4f0d2476ecdcb11a409
Enrichment time
2026-03-22T19:23:34Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Tycoon2FA Phishing-as-a-Service Platform Persists Following Takedown · Baitaphish