AI Phishing Is No. 1 With a Bullet for Cyberattackers

2026-04-24T14:51:51Za8118e6ed4ff51ecf1cff309a3e128c27f0d70956924a8de4fc2d7048d51d30e
2fa-phishingBYOVDCVE-2026-1731ai-phishingai-securityantigravitybomgarbotnetschina-aptclickfixcloud-espionagedevice-code-phishingdprkedr-killerlazarusnginxoauth-token-theftphishingrcesupply-chain-risktropic-trooperunpatched-exploitsvercelwhatsapp-metadatawindows-defender

What happened

A large DarkReading digest highlights a surge in AI-enabled phishing (including highly personalized 1-to-1 attacks) and multiple active threat trends: DPRK Lazarus/ClickFix campaigns targeting macOS, Tropic Trooper targeting home routers and Japanese entities, Chinese APTs abusing cloud apps to spy on Mongolia, and China-backed industrialization of botnets. Critical and actively exploited vulnerabilities are called out — notably a critical Bomgar RMM RCE (CVE-2026-1731) — plus three proof-of-concept Windows Defender exploits (two unpatched), an NGINX MCP integration flaw, and an RCE in Googleʼ

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
a8118e6ed4ff51ecf1cff309a3e128c27f0d70956924a8de4fc2d7048d51d30e
Enrichment time
2026-04-24T14:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.