Gen. partnerAlgotech

Week in Cybersecurity: Action Against Tycoon 2FA, Incidents in the Czech Republic, and New Vulnerabilities in Android and Cisco SD-WAN

The past week brought several important events in cybersecurity – from an international operation against a phishing infrastructure to new information on incidents in the Czech Republic and actively exploited vulnerabilities in Android and Cisco SD-WAN.

|
March 10, 2026
Week in Cybersecurity: Action Against Tycoon 2FA, Incidents in the Czech Republic, and New Vulnerabilities in Android and Cisco SD-WAN

The past week brought several important events in cybersecurity – from an international operation against a phishing infrastructure to new information on incidents in the Czech Republic and actively exploited vulnerabilities in Android and Cisco SD-WAN.

Microsoft, Europol a partneři zasáhli proti phishingové platformě Tycoon 2FA

An international operation led by Microsoft, Europol and other partners disrupted the operation of the phishing platform Tycoon 2FA, which was among the most prominent phishing-as-a-service offerings. Microsoft states that the platform’s infrastructure was linked to tens of millions of fraudulent emails per month and affected more than 500,000 organizations worldwide.

Tycoon 2FA has been active since at least 2023 and specialized in adversary-in-the-middle attacks. It was therefore not just about collecting passwords. The platform operated as a transparent proxy between the victim and the legitimate service, such as Microsoft 365 or Gmail. It forwarded login credentials and authentication challenges in real time and also captured session tokens and cookies, which allowed attackers to take over already authenticated sessions.

According to Microsoft, Tycoon 2FA accounted for approximately 62% of phishing attempts the company blocked in mid-2025, including more than 30 million emails in a single month. Since 2023 the service is associated with an estimated 96,000 distinct victims, of which more than 55,000 were Microsoft customers. The most affected sectors were healthcare and education.

Microsoft, under a court order, seized 330 active domains that formed the core of the Tycoon 2FA infrastructure. Security agencies in Latvia, Lithuania, Portugal, Poland, Spain and the United Kingdom also participated in the takedown. Cloudflare said it carried out a technical intervention against the Workers projects and infrastructure used by the phishing kit.

Cloudflare also notes that access to the service started at roughly $120, highlighting how low the entry barrier was for attackers.

The whole case again shows that multi-factor authentication significantly increases account security, but is not foolproof on its own. Against such proxy attacks, passkeys and hardware security keys are particularly resistant. This is explicitly recommended by the partners involved in the operation.

NÚKIB: v únoru evidoval v Česku 23 kybernetických incidentů

The National Cyber and Information Security Agency (NÚKIB) published a monthly incidents overview for February 2026. According to the report it recorded 23 cyber incidents. Compared to January this is a significant drop, but February still ended above the average of the past twelve months.

The main reason for the decrease was a lower number of recorded DDoS attacks, which NÚKIB says fell to roughly one third of January’s level. Conversely, the category intrusion increased, reaching its highest values in more than a year. About half of these incidents involved attacks on municipal map portals, while the rest included, for example, account compromises or edge device breaches.

The agency also recorded several cases of phishing, information leaks and data exfiltration. In terms of severity there were two significant incidents and 21 less significant incidents. It is also notable that this was the second month in a row without a recorded successful ransomware attack.

Android opravuje 129 zranitelností, jedna z nich mohla být zneužívána v cílených útocích

Google released the March Android Security Bulletin, which according to the summaries fixes 129 vulnerabilities. The most attention-grabbing issue is CVE-2026-21385, which Google describes in the official bulletin as potentially exploited in limited, targeted attacks.

In the official overview CVE-2026-21385 is listed among vulnerabilities in Qualcomm components, specifically in the Display subcomponent, and is rated High. The Android bulletin also reminds that devices with the 2026-03-05 patch level should include all relevant fixes from the March release.

In practice, distribution of fixes remains a problem. Google publishes the bulletin centrally, but the availability of updates depends on device manufacturers and their own update cycles.

Cisco varuje před aktivně zneužívanými chybami v Catalyst SD-WAN

Cisco and security partners recently warned of active exploitation of several vulnerabilities in Cisco Catalyst SD-WAN. The most severe is CVE-2026-20127, which Cisco describes as an authentication bypass issue. Successful exploitation could allow an attacker to obtain administrative privileges on the affected system. Cisco also stated it is aware of limited exploitation of this vulnerability.

The alert was followed by further warnings regarding the pair CVE-2026-20128 and CVE-2026-20122. Cisco later added that these two recently patched issues in Catalyst SD-WAN are also being actively exploited.

This is important for organizations mainly because the technology is used to manage and control enterprise WANs. A successful compromise can therefore impact the network infrastructure itself, not just an individual workstation or account.

Výzkumníci popsali novou samošířící kampaň v npm

Attention was also drawn to a new supply-chain campaign in the npm ecosystem. Researchers described an operation dubbed SANDWORM_MODE, in which 19 typosquatting packages were published on npmjs.com. According to available analysis, these packages stole credentials, infected projects and were designed to spread further among development environments.

This is another reminder that supply-chain attacks no longer target only large open-source libraries with millions of downloads, but also smaller packages that try to exploit developer inattention when installing dependencies.

Loading comments...

Stay in the loop

Subscribe to our newsletter and get the latest cybersecurity news delivered straight to your inbox.

Your data is safe. You can unsubscribe from the newsletter at any time.