[Podcast] It's not you, it's your printer: State-sponsored and phishing threats in 2025

2026-04-21T20:51:48Z2db61c339042627e72af6347fcbcd07f0b0e2655120ea9ab815fe076b5b34e1a
AI-driven threatsFoxitLibRawLucidRookMFA exploitationMicrosoft Patch TuesdayPowMix botnetmacOS LOTL techniquesn8n abusephishingransomware trendsstate-sponsored threatsvulnerabilities

What happened

Cisco Talos published a set of April 2026 posts covering multiple active threats and vulnerability trends: an increase in phishing that abuses MFA workflows and compromised trusted accounts; discovery of a new Lua-based backdoor family dubbed “LucidRook” used in targeted spear-phishing against Taiwanese NGOs and universities; an ongoing PowMix botnet campaign impacting Czech organizations (active since at least Dec 2025); disclosure and vendor patches for one Foxit Reader vulnerability and six LibRaw file-reader vulnerabilities; misuse of the n8n AI/workflow automation platform for email-based

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisco_talos
Record identifier
2db61c339042627e72af6347fcbcd07f0b0e2655120ea9ab815fe076b5b34e1a
Enrichment time
2026-04-21T20:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · [Podcast] It's not you, it's your printer: State-sponsored and phishing threats in 2025 · Baitaphish