Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks

2026-04-18T13:24:05Z46958bf0e3206d30f6f59fef6e27d71159da776d082808ad284248ac29122457
AI securityAnthropicApache ActiveMQCVE-2026-34197Chrome vulnerabilityCoChatCursor AIDraftKingsICSNorth KoreaShinyHuntersShowDocTycoon 2FAWhite HouseZionSiphondesalinationexploited in the wildphishingphishing kitsprompt injectionremote code executionremote tunnelsandbox bypassshadow AIwater treatment

What happened

This SecurityWeek roundup highlights multiple active and emerging threats plus policy and product developments. Key incidents: Tycoon 2FA phishing tooling—previously disrupted—has had its components reused across other phishing kits, driving a surge in phishing attacks; Apache ActiveMQ remote-code-execution vulnerability (CVE-2026-34197) is being exploited in the wild; ZionSiphon malware is targeting ICS systems tied to Israeli water-treatment and desalination facilities; and a Cursor AI issue (indirect prompt injection that can chain with a sandbox bypass and remote-tunnel feature) exposed at

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
46958bf0e3206d30f6f59fef6e27d71159da776d082808ad284248ac29122457
Enrichment time
2026-04-18T13:24:05Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.