IT Security Newsletter - 3/5/2026
Global coalition dismantles Tycoon 2FA phishing kit
Tycoon 2FA, a major phishing kit and platform that allowed low-skilled cybercriminals to bypass multifactor authentication and conduct large-scale adversary-in-the-middle attacks, was dismantled Wednesday by a global coalition of security companies and law enforcement agencies. Microsoft, which led the effort alongside Europol and authorities from six countries and 11 security firms or organizations, said it seized 330 domains that powered Tycoon 2FA's core infrastructure. READ MORE...
FBI seizes LeakBase cybercrime forum, data of 142,000 members
The FBI has seized the LeakBase cybercrime forum, a major online forum used by cybercriminals buy and sell hacking tools and stolen data. This seizure action is part of an international joint operation coordinated by Europol that involved law enforcement agencies in 14 countries. On March 3 and 4, the FBI and law enforcement agents shut down LeakBase by seizing two of its domains, posting seizure banners, and warning LeakBase members of the seizure after collecting further evidence. READ MORE...
LexisNexis confirms data breach at Legal & Professional arm, some customer records affected
Data analytics giant LexisNexis has confirmed its Legal & Professional division suffered a data breach days after the Fulcrumsec cybercrime crew claimed responsibility for the hack. Following an investigation, LexisNexis told The Register the matter is now contained, and that neither its products nor its services were ever compromised, although the company was forced to bring in a third-party digital forensics crew to manage the cleanup. READ MORE...
Iran-nexus hackers target flaws in surveillance cameras
Iran-linked hackers have stepped up attacks targeting IP cameras in recent days, exploiting critical flaws in widely used surveillance equipment. Since late February, hackers have been scanning for vulnerabilities in Hikvision and Dahua products, according to a blog post by Check Point Research. The flaws being targeted include a command injection flaw in Hikvision Intercom Broadcasting System, a remote-command execution vulnerability in Hikvision Security Management Platform. READ MORE...
LatAm Now Faces 2x More Cyberattacks Than US
Nowhere in the world has cyber threat activity been growing faster than in Latin America, thanks in part to relatively rapid digital adoption on the part of businesses in the region, combined with relatively stagnant cybersecurity growth. Last year, researchers at Check Point tracked a 53% year-over-year rise in weekly cyberattacks in Latin America, and as of 2026, they confirmed it to be the most heavily targeted region on the planet. READ MORE...
Russian Ransomware Operator Pleads Guilty in US
A 43-year-old Russian national has pleaded guilty in a US court to charges stemming from his role in the Phobos ransomware operation. The man, Evgenii Ptitsyn, was arrested in South Korea in June 2024 and extradited to the United States in November of the same year. The US Justice Department announced on Wednesday that Ptitsyn has now pleaded guilty to wire fraud conspiracy, for which he faces up to 20 years in prison. Sentencing is scheduled for July 15. READ MORE...
Cisco Warns of More Catalyst SD-WAN Flaws Exploited in the Wild
Cisco is warning customers that two recently patched Catalyst SD-WAN vulnerabilities are being exploited in the wild. The networking giant informed customers on February 25 about the availability of patches for five Catalyst SD-WAN flaws, including critical and high-severity issues that can be exploited to access vulnerable systems and elevate privileges to root. Cisco updated its advisory on March 5 to warn that it has become aware of active exploitation. READ MORE...
FreeScout vulnerability enables unauthenticated, zero-click RCE via email (CVE-2026-28289)
A newly discovered vulnerability (CVE-2026-28289) in the open-source help desk platform FreeScout could allow attackers to take over vulnerable servers by sending a specially crafted email to a FreeScout mailbox. FreeScout is a free, open-source help desk and shared inbox system used by businesses or teams to manage customer support conversations in one place. It's designed to be self-hosted - either on-premises, on a cloud server, or a virtual private server. READ MORE...
- ...in 1770, British troops fatally shoot five American civilians in Boston, a key event leading to the American Revolution.
- ...in 1910, Japanese businessman Momofuku Ando, the inventor of instant ramen noodles, is born in Taiwan.
- ...in 1946, Winston Churchill uses the phrase "Iron Curtain" to describe Soviet domination of Eastern Europe, in a speech at Westminster College in Fulton, MO.
- ...in 1955, stage magician and author Penn Jillette, of the comedy magic act Penn & Teller, is born in Greenfield, MA.







