Europol-Led Operation Takes Down Tycoon 2FA Phishing-as-a-Service Linked to 64,000 Attacks
2026-03-05T14:21:27Z•47de3c7d2dcf9bb5de8186aa45751f40d74ab28863cb2f701cd4fbceee9ea7a4
aitmapt28apt41chrome-webviewcisa-kevcorunacredential-harvestingexploit-kithavoc-c2ios-exploitsknown-exploited-vulnerabilitylaw-enforcement-takedownleakbasemshtml-0daynpm-malwarepackagist-malwarephishingphishing-as-a-servicequalcomm-androidremote-access-trojansilver-dragon-apt4x-clustered-activity?unknownstarkillersupply-chain-compromisetycoon-2favmware-aria
What happened
This collection of The Hacker News items reports a broad set of active cyber threats, law‑enforcement disruptions, and high‑impact vulnerabilities. Highlights include an Europol‑led takedown of the Tycoon 2FA phishing‑as‑a‑service and seizure of the LeakBase forum; active exploitation and KEV listing for VMware Aria Operations (CVE-2026-22719); an exploited Qualcomm Android graphics flaw (CVE-2026-21385); a patched Chrome WebView privilege escalation (CVE-2026-0628); and an MSHTML 0‑day tied to APT28 (CVE-2026-21513). Additional coverage describes widescale supply‑chain and registry abuse (mal
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 47de3c7d2dcf9bb5de8186aa45751f40d74ab28863cb2f701cd4fbceee9ea7a4
- Enrichment time
- 2026-03-05T14:21:27Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.