[Podcast] It's not you, it's your printer: State-sponsored and phishing threats in 2025
2026-04-22T08:51:55Z•26e065d4cc8bd9651a3cdb715296e47036de985505fff1112728fa9cefd6b24e
ai workflow abusebotnetcredential misuseczech republicfoxitlibrawliving-off-the-landlotllua malwarelucidrookmacosmfa exploitationmicrosoft patch tuesdaymulti-factor authenticationn8npatch managementphishingpowmixransomware trendsstate-sponsored activityvulnerabilitiesvulnerability management
What happened
Cisco Talos published a set of reports (April 2026) covering multiple active threats and trends: increased phishing and MFA-exploitation campaigns leveraging compromised/trusted accounts; abuse of agentic AI workflow platforms (n8n) in phishing lures; macOS living‑off‑the‑land techniques for movement and execution; disclosure of one Foxit Reader and six LibRaw file‑reader vulnerabilities (vendors patched); Q1 2026 vulnerability trends and the shrinking patch window; the PowMix botnet campaign affecting Czech organizations; and a new Lua‑based malware family dubbed “LucidRook” used in targeted,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisco_talos
- Record identifier
- 26e065d4cc8bd9651a3cdb715296e47036de985505fff1112728fa9cefd6b24e
- Enrichment time
- 2026-04-22T08:51:55Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.