Weekly review

ThreatNoir Weekend Brief — April 18

2026-04-18Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — April 18, 2026

The cybersecurity landscape on April 18, 2026 reflects an increasingly fragmented threat ecosystem where disrupted platforms spawn new attack variants, critical infrastructure remains vulnerable to exploitation, and zero-day vulnerabilities continue to threaten enterprise security tools. Today's developments underscore the persistent challenges organizations face in maintaining robust defenses against evolving threats.

Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks

Following the disruption of the Tycoon 2FA platform, threat actors have begun reusing its tools across alternative phishing kits, demonstrating the resilience of the Phishing-as-a-Service ecosystem. The displacement of Tycoon 2FA from its dominant position has not eliminated the threat but rather distributed it across competing platforms including EvilProxy, Mamba 2FA, and Sneaky 2FA. Source: Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks

This migration pattern reveals a critical vulnerability in the current approach to combating phishing infrastructure. Organizations relying solely on platform-specific defenses face significant risk as threat actors seamlessly transition between tools, maintaining operational capability despite law enforcement disruptions.

It Takes 2 Minutes to Hack the EU's New Age-Verification App

The European Union's newly developed age-verification application has been found to contain critical security flaws that can be exploited in approximately two minutes, raising serious questions about the adequacy of pre-release security testing. The vulnerability represents a significant gap in the vetting process for privacy-sensitive applications deployed at scale. Source: It Takes 2 Minutes to Hack the EU's New Age-Verification App

Beyond the age-verification application, the report also documents major data breaches affecting a gym chain and hotel giant, as well as a disruptive distributed denial-of-service attack targeting the Bluesky platform, illustrating the breadth of active threats across multiple sectors.

$13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims

Grinex, a Kyrgyzstan-incorporated cryptocurrency exchange previously sanctioned by both the United Kingdom and the United States, has suspended operations following a $13.74 million breach. The exchange attributed the attack to foreign intelligence agency involvement, citing operational hallmarks consistent with state-sponsored cyber activity. Source: $13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims

The incident, which involved the theft of cryptocurrency holdings exceeding the reported figure, represents a significant intersection of sanctions enforcement and cyber operations. The involvement of malware families such as Conti and Hydra suggests sophisticated technical capabilities deployed in the operation.

Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched

Huntress has disclosed that threat actors are actively exploiting three zero-day vulnerabilities in Microsoft Defender to achieve privilege escalation on compromised systems. The vulnerabilities, designated BlueHammer, RedSun, and UnDefend, were released by security researcher Chaotic Eclipse, with two remaining unpatched at the time of reporting. Source: Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched

The active exploitation of these flaws, including CVE-2026-33825, demonstrates the speed at which threat actors weaponize newly disclosed vulnerabilities in critical security infrastructure. The continued unpatched status of two of the three vulnerabilities creates an extended window of exposure for organizations relying on Microsoft Defender as a primary security control.

The convergence of these threats across phishing infrastructure, government applications, financial systems, and enterprise security tools underscores the need for comprehensive, layered security strategies that account for both the sophistication and adaptability of modern threat actors.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks
Malware4
  • Sneaky 2FA
    Competing PhaaS platform gaining market share post-Tycoon disruption
  • Tycoon 2FA
    Phishing-as-a-service platform disrupted by law enforcement; 330 domains seized in early March
  • EvilProxy
    Competing PhaaS platform gaining market share post-Tycoon disruption
  • Mamba 2FA
    Competing PhaaS platform gaining market share post-Tycoon disruption
Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched
CVE1
  • Microsoft Defender LPE vulnerability (BlueHammer), patched in Patch Tuesday
Malware3
  • UnDefend
    Denial-of-service vulnerability affecting Microsoft Defender definition updates, unpatched
  • RedSun
    Local privilege escalation vulnerability in Microsoft Defender, unpatched as of April 17, 2026
  • BlueHammer
    Local privilege escalation flaw in Microsoft Defender, exploited since April 10, 2026