New AITM phishing wave hijacks TikTok Business accounts

2026-03-27T20:51:51Z25f80d21a97d73fc5676a7068b4b08cee87b9cce03fc492f6995a87857c1b328
AITM-phishingBPFDoorCISA-KEVCVE-2025-15517CVE-2026-33017CVE-2026-33634CVE-2026-4681CorunaFlexPLMLangflowPTC-WindchillRed-MenshenTikTokTriangulationTrivyWebRTC-skimmeriOS-exploitmalvertisingpatchingpayment-skimmertelecom-espionageunpatched-vulnerability

What happened

This feed highlights multiple high-impact security developments: a new account-in-the-middle (AITM) phishing wave targeting TikTok for Business to hijack accounts for malvertising; a critical, currently unpatched PTC Windchill/FlexPLM vulnerability (CVE-2026-4681, CVSS 10.0) flagged by CISA and BSI with potential imminent exploitation; CISA additions to its Known Exploited Vulnerabilities (KEV) catalog for Aquasecurity Trivy (CVE-2026-33634, CVSS 9.3) and Langflow (CVE-2026-33017, CVSS 9.3); discovery of stealthy BPFDoor implants used by China-linked Red Menshen APT against telecom networks; a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
25f80d21a97d73fc5676a7068b4b08cee87b9cce03fc492f6995a87857c1b328
Enrichment time
2026-03-27T20:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.