New Wave of AiTM Phishing Targets TikTok for Business
2026-03-27T20:52:18Z•0350bf0f99c1c3e0cdc75965ad2880c34a5abe15e868094a61c6f7fa8d998271
AI-generated code vulnerabilitiesAiTM phishingCVE-2026-20131CVE-2026-3888Cisco zero-dayEtherRATEthereum smart-contract C2Langflow exploitLiteLLMOpenAI bug bountyOracle WebLogic RCEPay2Key resurgencePyPI compromiseTeamPCPTikTok for BusinessTrivy Docker compromiseTycoon2FAUK sanctions (Xinbi)Ubuntu local rootcredential stealernpm ghost campaignphishingpost-quantum/quantum threatransomwaresupply-chain attack
What happened
Multiple active and emerging threats across phishing, software supply chains, and critical infrastructure vulnerabilities. Push Security and others report a rise in AiTM phishing (targeting TikTok for Business) and resumed Tycoon2FA operations; TeamPCP continues to compromise PyPI/npm/Docker ecosystems (LiteLLM, Telnyx package, Trivy images) to deliver credential-stealing malware; honeypots show rapid weaponization of critical Oracle WebLogic RCEs and Langflow flaws; attackers have been abusing a Cisco zero-day (CVE-2026-20131) in ransomware campaigns. Additional notable items include EtherRAT
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 0350bf0f99c1c3e0cdc75965ad2880c34a5abe15e868094a61c6f7fa8d998271
- Enrichment time
- 2026-03-27T20:52:18Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.