Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (5 March 2026)
Published: Loading…
At a Glance
- Europol-led operation dismantled the Tycoon2FA phishing platform, seizing more than 300 domains used to bypass MFA and target over 500,000 organisations.
- CISA added Qualcomm chipset flaw CVE-2026-21385 and VMware Aria Operations command injection CVE-2026-22719 to its Known Exploited Vulnerabilities catalogue.
- The Coruna exploit kit uses 23 iOS vulnerabilities across five chains targeting iPhones running iOS 13 through 17.2.1 in espionage and financial attacks.
- Iran-linked hackers attempted to compromise Hikvision and Dahua surveillance cameras across Israel and Middle Eastern countries during ongoing missile strikes.
- Attackers abused OAuth error redirects to move victims from legitimate Microsoft or Google login pages to phishing and malware sites.
- A critical Azure Data Explorer flaw allowed attackers to exfiltrate cross-tenant data through malicious dashboards executing Kusto queries with victim permissions.
Summary
International law enforcement action dismantled the Tycoon2FA phishing-as-a-service platform after infrastructure linked to adversary-in-the-middle credential harvesting was seized. The service enabled attackers to intercept credentials and session cookies from Microsoft 365 and Gmail accounts while distributing phishing campaigns that reached hundreds of thousands of organisations.
Exploitation of widely deployed software remained a central issue, with CISA confirming active attacks against CVE-2026-22719 in VMware Aria Operations and CVE-2026-21385 affecting Qualcomm chipsets. Additional exposure surfaced through Azure Data Explorer, where cross-tenant dashboard sharing could execute malicious Kusto queries under victim credentials and expose sensitive cluster data.
Mobile platform exploitation continued to expand with the appearance of the Coruna exploit kit targeting iPhones running iOS 13–17.2.1. The toolkit contains 23 vulnerabilities organised into five exploit chains and has been used in espionage campaigns as well as financially motivated operations including cryptocurrency theft.
Geopolitical tensions also intersected with cyber activity as Iran-linked infrastructure targeted Hikvision and Dahua surveillance cameras across Israel and multiple Middle Eastern countries. The activity coincided with regional missile strikes and involved attempts to compromise internet-connected cameras to obtain visual intelligence.
Credential-theft techniques continued evolving through abuse of authentication infrastructure. Attackers exploited OAuth error redirects in Microsoft and Google authentication flows to redirect victims to attacker-controlled phishing or malware pages without completing legitimate sign-in processes.
Malicious software distribution and infrastructure abuse persisted across developer ecosystems and enterprise platforms. Fake Laravel packages on Packagist delivered cross-platform remote access trojans to Windows, macOS, and Linux systems, while the FreeScout Mail2Shell vulnerability enabled zero-click remote code execution against exposed helpdesk servers.
Highlights of the Day
CISA Adds Qualcomm and VMware Flaws to Exploited Vulnerabilities List
The US Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation. The newly listed flaws include a memory corruption issue affecting multiple Qualcomm chipsets (CVE-2026-21385) and a command injection vulnerability in Broadcom’s VMware Aria Operations (CVE-2026-22719). CISA maintains the catalogue as part of a directive requiring US federal civilian agencies to track and remediate vulnerabilities linked to active threats.
Coruna iPhone Exploit Kit Circulates Among Multiple Threat Actors
Researchers have identified a sophisticated iOS exploit kit known as Coruna, containing 23 vulnerabilities and five full exploit chains targeting iPhones running iOS 13 through 17.2.1. Google observed the toolkit used in targeted espionage operations and later in broader campaigns linked to financially motivated actors, indicating its spread across different groups. Claims that the kit is connected to the earlier Operation Triangulation campaign attributed to US intelligence have been disputed by Kaspersky, which reported no evidence of shared code.
Iranian Hackers Target IP Cameras During Middle East Conflict
Researchers report a surge in attempts to compromise internet-connected cameras across Israel and several Middle Eastern countries, activity linked to infrastructure associated with Iranian threat actors. The campaigns focus on vulnerabilities in widely deployed Hikvision and Dahua devices and have been observed alongside periods of heightened regional tensions and missile activity. Analysts say the targeting pattern is consistent with the use of compromised cameras to gather visual intelligence and assess the impact of military strikes.
Azure Data Explorer Flaw Allowed Cross-Tenant Data Exfiltration
Researchers disclosed a critical vulnerability in Microsoft Azure Data Explorer that could expose sensitive data across tenants through the platform’s dashboard sharing feature. The flaw allowed attackers to craft dashboards containing malicious Kusto Query Language (KQL) queries that executed using a victim’s permissions once the shared dashboard was opened. Query results could then be captured in the attacker’s logs, enabling extraction of private data from the victim’s cluster.
Tycoon2FA Phishing Platform Disrupted After Global MFA Bypass Campaigns
A coordinated operation involving Europol, Microsoft, and multiple industry partners has disrupted the Tycoon2FA phishing-as-a-service platform, seizing more than 300 domains linked to its infrastructure. The service enabled adversary-in-the-middle attacks that intercepted credentials, multifactor authentication codes, and session cookies from services such as Microsoft 365 and Gmail, supporting large-scale phishing campaigns used by thousands of operators. Researchers report the platform sent tens of millions of phishing messages monthly and relied on rapidly rotating domains and customised phishing pages to evade detection.
Daily Coverage