[Podcast] It's not you, it's your printer: State-sponsored and phishing threats in 2025

2026-04-22T08:51:55Z26e065d4cc8bd9651a3cdb715296e47036de985505fff1112728fa9cefd6b24e
ai workflow abusebotnetcredential misuseczech republicfoxitlibrawliving-off-the-landlotllua malwarelucidrookmacosmfa exploitationmicrosoft patch tuesdaymulti-factor authenticationn8npatch managementphishingpowmixransomware trendsstate-sponsored activityvulnerabilitiesvulnerability management

What happened

Cisco Talos published a set of reports (April 2026) covering multiple active threats and trends: increased phishing and MFA-exploitation campaigns leveraging compromised/trusted accounts; abuse of agentic AI workflow platforms (n8n) in phishing lures; macOS living‑off‑the‑land techniques for movement and execution; disclosure of one Foxit Reader and six LibRaw file‑reader vulnerabilities (vendors patched); Q1 2026 vulnerability trends and the shrinking patch window; the PowMix botnet campaign affecting Czech organizations; and a new Lua‑based malware family dubbed “LucidRook” used in targeted,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisco_talos
Record identifier
26e065d4cc8bd9651a3cdb715296e47036de985505fff1112728fa9cefd6b24e
Enrichment time
2026-04-22T08:51:55Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.