Europol and partners from 14 countries dismantled LeakBase, a major open‑web marketplace for breached databases and “stealer logs,” seizing infrastructure and disrupting a community of more than 142,000 registered users. The forum served as a hub for account takeover and downstream intrusions; its removal will ripple across infostealer and credential-stuffing operations, at least temporarily increasing friction for buyers and sellers.
Source: Europol
Authorities pull plug on Tycoon 2FA phishing-as-a-service that helped bypass MFA at scale
Law enforcement and industry partners disrupted Tycoon 2FA, a subscription PhaaS that let criminals conduct adversary‑in‑the‑middle phishing to defeat multi‑factor authentication. Investigators say the kit was responsible for a large share of recent phishing attempts, underscoring the need for phishing‑resistant MFA (FIDO2/WebAuthn), conditional access, and hardened session token protections.
Source: Help Net Security
Android March patches fix 129 flaws, including an actively exploited Qualcomm bug
Google shipped fixes for 129 Android vulnerabilities, notably an in‑the‑wild exploit against a widely used Qualcomm component. Mobile fleets should prioritize this month’s updates via MDM, especially on devices with Qualcomm chipsets, to reduce exposure to targeted attacks already observed in the wild.
Source: Malwarebytes
Nation-state “Coruna” iOS exploit kit surfaces in broader campaigns; update to latest iOS
Researchers detailed Coruna, a powerful iOS exploit kit first tied to Russian state activity that packages 23 exploits across five chains targeting iOS 13–17.2.1. While ineffective against the latest iOS release, the kit’s migration into criminal operations raises the stakes for lagging devices—organizations should enforce rapid iOS updates and limit high‑risk browsing on unmanaged phones.
Source: SecurityWeek
VMware Aria Operations RCE (CVE-2026-22719) exploited in the wild; on CISA’s KEV list
A recently patched Aria Operations command injection flaw allows unauthenticated remote code execution and is now under active exploitation. Admins should apply Broadcom’s February 24 fix immediately, restrict management interfaces, and monitor for post‑exploitation activity, as CISA has added the bug to its Known Exploited Vulnerabilities catalog.
Source: SecurityWeek
Attackers abuse OAuth redirects from legit Microsoft/Google logins to phishing and malware
Researchers warn that adversaries are crafting OAuth URLs that intentionally trigger redirects from genuine Microsoft or Google login flows to malicious destinations. Because the journey starts on a trusted screen, users are more likely to comply—security teams should lock down redirect URIs, block open redirects, enforce PKCE, and train users to spot suspicious consent flows.
Source: Malwarebytes
Cisco Talos: China‑nexus UAT‑9244 hits South American telecoms with three new implants
Cisco Talos exposed UAT‑9244, assessed with high confidence as a China‑nexus APT linked to Famous Sparrow, targeting telecommunications providers in South America. The campaign debuted three previously unseen implants, signaling ongoing investment in bespoke tooling against critical infrastructure and reinforcing the urgency of robust segmentation, monitoring, and supply‑chain vetting in telco environments.
Source: Cisco Talos
You May Also Be Interested In...
Supreme Court to decide whether geofence warrants are constitutionalCisco patches 48 vulnerabilities across ASA, Secure FMC, and Secure FTD
Hacktivist DDoS surges after Middle East conflict: 149 attacks across 16 countries