BT
Privacy ToolboxJournalProjectsResumeBookmarks
Feed
Privacy Toolbox
Journal
Projects
Resume
Bookmarks
Intel
Threat Actors
Privacy Threats
Dashboard
CVEs
Tags
Intel
Threat ActorsPrivacy ThreatsDashboardCVEsTags

Intel

  • Feed
  • Threat Actors
  • Privacy Threats
  • Dashboard
  • Privacy Toolbox
  • CVEs

Personal

  • Journal
  • Projects

Resources

  • Subscribe
  • Bookmarks
  • Developers
  • Tags
Cybersecurity News & Analysis
github
defconxt
•
© 2026
•
blacktemple.net
  1. Feed
  2. /Malware Roundup: Healthcare Breach Hits 3.4M, CISA Orders iOS Patches, Phishing Kit Takedown

Malware Roundup: Healthcare Breach Hits 3.4M, CISA Orders iOS Patches, Phishing Kit Takedown

March 7, 2026Malware & Threats3 min readhigh

Originally reported by BleepingComputer, Graham Cluley, Malwarebytes Labs

#healthcare-breach#ios-vulnerabilities#phishing-kit#infostealer#social-engineering#mfa-bypass#trizetto#tycoon-2fa
Share

TL;DR

TriZetto suffered a breach exposing 3.4 million patient records while CISA ordered federal agencies to patch three iOS vulnerabilities actively exploited in crypto-theft attacks. Law enforcement successfully dismantled the Tycoon 2FA phishing-as-a-service platform that enabled MFA bypass attacks.

Why high?

CISA ordered federal agencies to patch actively exploited iOS vulnerabilities combined with a major healthcare breach affecting 3.4 million patients elevates this to high severity.

Major Stories

TriZetto Healthcare Breach Exposes 3.4 Million Patient Records

Cognizant's TriZetto Provider Solutions experienced a data breach affecting over 3.4 million individuals, marking another significant healthcare sector incident. TriZetto develops software and services used by health insurers and healthcare providers, making the breach particularly concerning given the sensitivity of healthcare data and the broad ecosystem impact. The company has not disclosed specific details about the attack vector or timeline, following the typical pattern of healthcare breaches where technical details emerge gradually through regulatory filings.

CISA Orders Federal Agencies to Patch Actively Exploited iOS Vulnerabilities

CISA issued a directive requiring U.S. federal agencies to patch three iOS security vulnerabilities currently being exploited in cyberespionage and cryptocurrency theft attacks. The exploits are part of the Coruna exploit kit, indicating a sophisticated threat actor capability. The federal mandate underscores the severity of these vulnerabilities and suggests they pose risks beyond typical consumer-focused attacks. Organizations should prioritize these patches given the confirmed active exploitation.

Law Enforcement Dismantles Tycoon 2FA Phishing Platform

International law enforcement agencies successfully shut down Tycoon 2FA, described as one of the world's most prolific phishing-as-a-service platforms. The $120 phishing kit enabled attackers to bypass multi-factor authentication, demonstrating how commoditized MFA bypass techniques have become in the threat landscape. This takedown represents a significant disruption to the phishing ecosystem, though similar services will likely emerge to fill the void.

Emerging Threats

InstallFix Social Engineering Targets Developer Tools

Threat actors deployed a new social engineering technique called InstallFix, masquerading as legitimate installation guides for command-line tools like Claude Code. The campaign tricks users into running malicious commands that deploy infostealers, targeting developers who frequently install CLI tools. This represents an evolution of the ClickFix technique, adapting social engineering to developer workflows and trusted software installation processes.

Fake Google Meet Update Enables Remote Device Management

Malwarebytes researchers discovered a campaign using fraudulent Google Meet updates to enroll victim Windows PCs into attacker-controlled device management systems. This technique provides persistent access and administrative control over compromised systems, going beyond traditional malware installation. The use of legitimate device management capabilities for malicious purposes represents a concerning trend in attack sophistication.

Industry Updates

EC-Council Launches AI-Focused Certification Suite

EC-Council announced its Enterprise AI Credential Suite, introducing four role-based AI certifications alongside an updated Certified CISO v4 program. The certifications aim to address the growing intersection of AI and cybersecurity, reflecting industry recognition of AI-specific security challenges and workforce development needs.

Microsoft 365 Backup Adds File-Level Restoration

Microsoft announced upcoming file-level restore capabilities for Microsoft 365 Backup, enabling administrators to recover individual files and folders rather than entire datasets. This enhancement addresses ransomware recovery scenarios where granular restoration can significantly reduce recovery time and business impact.

Sources

  • https://www.bleepingcomputer.com/news/security/cognizant-trizetto-breach-exposes-health-data-of-34-million-patients/
  • https://www.bleepingcomputer.com/news/security/cisa-warns-of-apple-flaws-exploited-in-spyware-crypto-theft-attacks/
  • https://www.bleepingcomputer.com/news/security/ec-council-expands-ai-certification-portfolio-to-strengthen-us-ai-workforce-readiness-and-security/
  • https://www.bleepingcomputer.com/news/security/fake-claude-code-install-guides-push-infostealers-in-installfix-attacks/
  • https://www.bleepingcomputer.com/news/microsoft/microsoft-365-backup-to-add-file-level-restore-for-faster-recovery/
  • https://www.bitdefender.com/en-us/blog/hotforsecurity/hackers-bypassed-mfa-120-phishing-kit-global-takedown-shut-down
  • https://www.malwarebytes.com/blog/threat-intel/2026/03/one-click-on-this-fake-google-meet-update-can-give-attackers-control-of-your-pc

Originally reported by BleepingComputer, Graham Cluley, Malwarebytes Labs

Tags

#healthcare-breach#ios-vulnerabilities#phishing-kit#infostealer#social-engineering#mfa-bypass#trizetto#tycoon-2fa

Tracked Companies

🇺🇸Google
🇺🇸Apple

Related Intelligence

  • Trojanized Red Alert App Targets Israeli Users via Fake Government SMS

    highMar 8, 2026
  • Velvet Tempest Links Termite Ransomware to ClickFix CastleRAT Campaign

    highMar 8, 2026
  • ClickFix Campaign Expands to Target Cryptocurrency Wallets and 25+ Browsers

    mediumFeb 22, 2026

Explore

  • Dashboard
  • Privacy Threats
  • Threat Actors
← Back to the feed

Previous Article

← Nation-State Ops Escalate: AI-Enhanced Infiltration and Cyber-Kinetic Warfare Converge

Next Article

Iranian APT Groups Intensify Cyber Operations Against U.S. and Middle East Infrastructure →