Microsoft Reveals ClickFix Campaign Using Windows Terminal to Deploy Lumma Stealer

Microsoft revealed a new phishing campaign, ClickFix, using Windows Terminal to deploy Lumma Stealer malware. The campaign tricks users into executing commands via a trusted app, bypassing detection methods aimed at the Run dialog. It executes a multi-stage attack: downloading and extracting malicious scripts, collecting credentials from browsers, and establishing persistence. The malware targets sensitive data, emphasizing the risks of social engineering tactics in cybersecurity.

https://thehackernews.com/2026/03/microsoft-reveals-clickfix-campaign.html

Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit

Google's Threat Intelligence Group identified a new iOS exploit kit, “Coruna,” targeting iPhone models from iOS 13.0 to 17.2.1. Coruna comprises five exploit chains and uses advanced techniques to bypass mitigations. It was initially discovered with links to commercial surveillance, later leveraged by Russian espionage and Chinese financial criminals. Users are urged to update their devices to the latest iOS version or enable Lockdown Mode for security. The kit features sophisticated mechanisms for targeting and data theft, indicating a growing market for reused zero-day exploits.

https://cloud.google.com/blog/topics/threat-intelligence/coruna-powerful-ios-exploit-kit

APT36: a Nightmare of Vibeware

APT36, known as Transparent Tribe, shifts from conventional malware to “vibeware,” an AI-generated model producing numerous low-quality implants using niche languages like Nim, Zig, and Crystal. This evolution aims to evade detection and employs trusted cloud services for command and control. Despite technical flaws leading to ineffective malware, this model's production volume overwhelms defenses, indicating a trend towards automated, high-volume cyberattacks. Their targeted attacks focus on the Indian government, utilizing sophisticated social engineering tactics and established frameworks alongside new, poorly coded variants. Overall, APT36 embraces a strategy of integrating AI into malware design, resulting in mass-produced threats lacking true innovation but full of operational risk.

https://businessinsights.bitdefender.com/apt36-nightmare-vibeware

Abusing .arpa: The TLD That Isn’t Supposed to Host Anything

Threat actors are exploiting the .arpa top-level domain (TLD), typically not meant for hosting content, to conduct phishing attacks. By using IPv6 tunnels, they create malicious domains that bypass security controls. These phishing campaigns employ tricks like embedding hyperlinks in images, leading victims to malicious sites through a series of redirects. The attack involves manipulating DNS record management to host phishing content, taking advantage of the .arpa domain’s trusted nature. This novel exploitation complicates detection since these domains appear legitimate and are often unblocked by security policies.

https://www.infoblox.com/blog/threat-intelligence/abusing-arpa-the-tld-that-isnt-supposed-to-host-anything/

United States Leads Dismantlement of One of the World’s Largest Hacker

The Department of Justice announced the seizure of the LeakBase database, a major online forum for cybercriminals. Coordinated actions by law enforcement in 14 countries, including the United States, shut down the forum, seized data, and arrested individuals involved. This operation disrupts a significant platform for cybercriminals to profit from stolen data and demonstrates international cooperation in combating cybercrime.

https://www.justice.gov/opa/pr/united-states-leads-dismantlement-one-worlds-largest-hacker-forums

Inside Tycoon2FA: How a Leading AiTM Phishing Kit Operated at Scale

The article analyzes Tycoon2FA, a phishing-as-a-service platform that enabled large-scale adversary-in-the-middle (AiTM) attacks capable of bypassing multifactor authentication. It explains how the service intercepted login credentials and session cookies through proxy phishing pages that mimicked services such as Microsoft 365 and Gmail. The platform included evasion techniques and user-friendly infrastructure, enabling less-skilled attackers to run campaigns that reached hundreds of thousands of organizations each month. The article concludes with guidance on layered defenses, including improved authentication methods, phishing detection, and coordinated disruption efforts. 

https://www.microsoft.com/en-us/security/blog/2026/03/04/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale/

Global Phishing-as-a-service Platform Taken Down in Coordinated Public-private Action

Tycoon 2FA, a major phishing-as-a-service platform, was disrupted in a coordinated international operation led by Europol. The platform, which enabled large-scale account compromise, was taken down with the help of law enforcement and private sector partners, including Microsoft and Trend Micro. This operation highlights the importance of public-private partnerships in combating cybercrime.

https://www.europol.europa.eu/media-press/newsroom/news/global-phishing-service-platform-taken-down-in-coordinated-public-private-action

LLMs Can Unmask Pseudonymous Users at Scale With Surprising Accuracy

Large language models (LLMs) can accurately unmask pseudonymous users on social media platforms, thereby undermining the privacy afforded by pseudonymity. Researchers found that LLMs can achieve high recall and precision rates in identifying users based on their online activity, posing risks of doxxing, stalking, and targeted advertising. The study highlights the need for stronger privacy protections and suggests mitigations, such as rate limits on data access and monitoring for LLM misuse.

https://arstechnica.com/security/2026/03/llms-can-unmask-pseudonymous-users-at-scale-with-surprising-accuracy/

Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild

IDPI exploits hidden instructions in web content processed by LLMs, causing unauthorized actions without direct interaction. Recent evidence shows substantial real-world malicious exploitation, including AI ad review evasion and SEO manipulation targeting phishing. 22 techniques were identified, necessitating proactive defenses against such threats. Understanding and mitigating web-based IDPI is crucial for the safety of AI systems integrated into web operations.

https://unit42.paloaltonetworks.com/ai-agent-prompt-injection/

Link11 Releases European Cyber Report 2026: DDoS Attacks Become a Constant Threat

DDoS attacks surged in 2025, with a 75% increase, becoming a constant threat to digital infrastructures in Europe. Attacks lasted up to 12,388 minutes, and follow-up incidents increased by 80%. Link11 recommends continuous DDoS protection, advanced web application security, and AI-based detection for resilience against evolving threats.

https://markets.businessinsider.com/news/currencies/link11-releases-european-cyber-report-2026-ddos-attacks-become-a-constant-threat-1035885265

New Gmail Account Attack Warning—Hackers Abuse Critical Security Check

Hackers are targeting Gmail users with a malicious fake Google Account Security Checkup tool that grants attackers access to sensitive information, including push notifications, contacts, GPS location, and clipboard contents. This attack uses deception to trick users into following prompts that compromise their account security. To protect themselves, users should only use the official Google Account Security Checkup tool through official channels, such as typing the URL directly into their browser.

https://www.forbes.com/sites/daveywinder/2026/03/01/check-your-gmail-account-security-now-ongoing-attacks-reported/

US‑Israel‑Iran Conflict May Trigger Unprecedented Cyberattacks

US-Israel-Iran tensions may lead to extensive cyberattacks disrupting critical infrastructure and financial systems. Cyberwarfare is increasingly integrated into military strategies, as past incidents demonstrate its potential for widespread damage without physical destruction. Experts warn that the ongoing conflict could escalate into coordinated attacks on various sectors, stressing the need for robust cybersecurity measures like zero-trust architecture.

https://www.khaleejtimes.com/world/asia/usisraeliran-trigger-unprecedented-cyberattacks?amp=1

Scroll to Top