Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks
2026-04-18T13:24:05Z•46958bf0e3206d30f6f59fef6e27d71159da776d082808ad284248ac29122457
AI securityAnthropicApache ActiveMQCVE-2026-34197Chrome vulnerabilityCoChatCursor AIDraftKingsICSNorth KoreaShinyHuntersShowDocTycoon 2FAWhite HouseZionSiphondesalinationexploited in the wildphishingphishing kitsprompt injectionremote code executionremote tunnelsandbox bypassshadow AIwater treatment
What happened
This SecurityWeek roundup highlights multiple active and emerging threats plus policy and product developments. Key incidents: Tycoon 2FA phishing tooling—previously disrupted—has had its components reused across other phishing kits, driving a surge in phishing attacks; Apache ActiveMQ remote-code-execution vulnerability (CVE-2026-34197) is being exploited in the wild; ZionSiphon malware is targeting ICS systems tied to Israeli water-treatment and desalination facilities; and a Cursor AI issue (indirect prompt injection that can chain with a sandbox bypass and remote-tunnel feature) exposed at
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 46958bf0e3206d30f6f59fef6e27d71159da776d082808ad284248ac29122457
- Enrichment time
- 2026-04-18T13:24:05Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.