Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks

2026-04-19T13:24:10Z5ac7ca8a465beb6035ef627670c6bd92aa764319db31ecf0e212e5afed84e2ea
AI-governanceActiveMQAnthropicCVE-2026-34197Chrome-vulnerabilityCoChatCursor AIICSShowDocTycoon 2FAZionSiphoncredential-theftexploited-in-the-wildlaw-enforcementphishingphishing-kitsprompt-injectionremote-tunnelsandbox-bypasswater-infrastructure

What happened

This batch highlights an uptick in active exploitation and targeted campaigns: the Apache ActiveMQ RCE tracked as CVE-2026-34197 is being exploited in the wild, while ZionSiphon malware is targeting Israeli water-treatment and desalination ICS. Phishing activity is surging as Tycoon 2FA tools are being reused across other phishing kits. A Cursor AI vulnerability could be chained (prompt injection + sandbox bypass + remote tunnel) to get shell access to developer machines. Additional items cover AI governance engagement with Anthropic, a new enterprise AI collaboration product (CoChat) to curb

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
5ac7ca8a465beb6035ef627670c6bd92aa764319db31ecf0e212e5afed84e2ea
Enrichment time
2026-04-19T13:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.