Microsoft Patch Tuesday for April 2026 - Snort Rule and Prominent Vulnerabilities
2026-04-14T20:51:54Z•4c7c220a1c26c91a29b1fdf8a6fbebf32ada15a7fd0813ef918c101b4f27ebaf
axios npmcredential harvestingedr evasionlua malwarelucidrookmicrosoft patch tuesdaymsimg32.dllnexus listenerpatch windowqilin ransomwareransomware trendssaas notification pipelinessnort rulesspear-phishingstate-sponsored threatssupply chain attacktaiwan-targetinguat-10608vulnerabilitiesyear in review
What happened
Cisco Talos April 2026 feed: Microsoft Patch Tuesday (includes Snort rule updates and notable Microsoft vulnerabilities), analysis of accelerating exploitation and shrinking patch windows, and examinations of state-sponsored actor tradecraft (China, Russia, North Korea, Iran). Notable incident reporting includes a new Lua-based malware family “LucidRook” used in targeted spear-phishing against Taiwanese NGOs and universities; a large-scale automated credential harvesting campaign (UAT-10608) leveraging the “NEXUS Listener” framework; Qilin ransomware’s EDR-evasion infection chain using a rogue
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisco_talos
- Record identifier
- 4c7c220a1c26c91a29b1fdf8a6fbebf32ada15a7fd0813ef918c101b4f27ebaf
- Enrichment time
- 2026-04-14T20:51:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.