Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks
2026-04-19T13:24:10Z•5ac7ca8a465beb6035ef627670c6bd92aa764319db31ecf0e212e5afed84e2ea
AI-governanceActiveMQAnthropicCVE-2026-34197Chrome-vulnerabilityCoChatCursor AIICSShowDocTycoon 2FAZionSiphoncredential-theftexploited-in-the-wildlaw-enforcementphishingphishing-kitsprompt-injectionremote-tunnelsandbox-bypasswater-infrastructure
What happened
This batch highlights an uptick in active exploitation and targeted campaigns: the Apache ActiveMQ RCE tracked as CVE-2026-34197 is being exploited in the wild, while ZionSiphon malware is targeting Israeli water-treatment and desalination ICS. Phishing activity is surging as Tycoon 2FA tools are being reused across other phishing kits. A Cursor AI vulnerability could be chained (prompt injection + sandbox bypass + remote tunnel) to get shell access to developer machines. Additional items cover AI governance engagement with Anthropic, a new enterprise AI collaboration product (CoChat) to curb
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 5ac7ca8a465beb6035ef627670c6bd92aa764319db31ecf0e212e5afed84e2ea
- Enrichment time
- 2026-04-19T13:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.