NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts
2026-04-02T14:52:19Z•0aaf2e4fb17b9ce359d6efd3a07634ada8c61543af4657f249df5f470407e7d6
AiTM-phishingandroidcitrix-netscalercredential-theftcritical-vulnerabilitydeeploadetherrat","ai-security","ai-generated-codeexploit-in-the-wildf5-big-ipfast-paced-attacksgithub-c2infostealeriosmalware-as-a-servicemobile-securityncsc-alertnpmoracle-weblogicpatching-advisoryphantom-stealerphishingpypiransomwaresupply-chain-compromisevenom-stealer
What happened
Multiple active high-impact threats and trends: attackers are actively exploiting critical infrastructure vulnerabilities (notably Citrix NetScaler CVE-2026-3055 and F5 BIG‑IP CVE-2025-53521) and rapidly weaponising Oracle WebLogic RCEs. Ransomware (Akira, Pay2Key) and ultra-fast extortion campaigns are rising, while malware-as-a-service and new stealers (Venom, Phantom, DeepLoad, EtherRAT) automate credential and crypto theft. Supply‑chain compromises (npm axios, PyPI LiteLLM, TeamPCP), GitHub used as covert C2, and AiTM phishing (TikTok for Business) threaten credentials at scale. Platforms/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 0aaf2e4fb17b9ce359d6efd3a07634ada8c61543af4657f249df5f470407e7d6
- Enrichment time
- 2026-04-02T14:52:19Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.