Europol-Led Operation Takes Down Tycoon 2FA Phishing-as-a-Service Linked to 64,000 Attacks

2026-03-05T14:21:27Z47de3c7d2dcf9bb5de8186aa45751f40d74ab28863cb2f701cd4fbceee9ea7a4
aitmapt28apt41chrome-webviewcisa-kevcorunacredential-harvestingexploit-kithavoc-c2ios-exploitsknown-exploited-vulnerabilitylaw-enforcement-takedownleakbasemshtml-0daynpm-malwarepackagist-malwarephishingphishing-as-a-servicequalcomm-androidremote-access-trojansilver-dragon-apt4x-clustered-activity?unknownstarkillersupply-chain-compromisetycoon-2favmware-aria

What happened

This collection of The Hacker News items reports a broad set of active cyber threats, law‑enforcement disruptions, and high‑impact vulnerabilities. Highlights include an Europol‑led takedown of the Tycoon 2FA phishing‑as‑a‑service and seizure of the LeakBase forum; active exploitation and KEV listing for VMware Aria Operations (CVE-2026-22719); an exploited Qualcomm Android graphics flaw (CVE-2026-21385); a patched Chrome WebView privilege escalation (CVE-2026-0628); and an MSHTML 0‑day tied to APT28 (CVE-2026-21513). Additional coverage describes widescale supply‑chain and registry abuse (mal

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
47de3c7d2dcf9bb5de8186aa45751f40d74ab28863cb2f701cd4fbceee9ea7a4
Enrichment time
2026-03-05T14:21:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.