AI Phishing Is No. 1 With a Bullet for Cyberattackers
2026-04-24T14:51:51Z•a8118e6ed4ff51ecf1cff309a3e128c27f0d70956924a8de4fc2d7048d51d30e
2fa-phishingBYOVDCVE-2026-1731ai-phishingai-securityantigravitybomgarbotnetschina-aptclickfixcloud-espionagedevice-code-phishingdprkedr-killerlazarusnginxoauth-token-theftphishingrcesupply-chain-risktropic-trooperunpatched-exploitsvercelwhatsapp-metadatawindows-defender
What happened
A large DarkReading digest highlights a surge in AI-enabled phishing (including highly personalized 1-to-1 attacks) and multiple active threat trends: DPRK Lazarus/ClickFix campaigns targeting macOS, Tropic Trooper targeting home routers and Japanese entities, Chinese APTs abusing cloud apps to spy on Mongolia, and China-backed industrialization of botnets. Critical and actively exploited vulnerabilities are called out — notably a critical Bomgar RMM RCE (CVE-2026-1731) — plus three proof-of-concept Windows Defender exploits (two unpatched), an NGINX MCP integration flaw, and an RCE in Googleʼ
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- a8118e6ed4ff51ecf1cff309a3e128c27f0d70956924a8de4fc2d7048d51d30e
- Enrichment time
- 2026-04-24T14:51:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.