Cybersecurity Daily Briefing: April 10, 2026

Coverage: Last 24 hours

Today’s Highlights

Today’s news centers on targeted malware campaigns, phishing attacks against executives, critical plugin supply chain compromises, and browser security improvements. Defenders should focus on detection and response for advanced persistent threats, phishing targeting privileged users, and incidents exploiting trust in third-party software dependencies.

Table of Contents

  1. New ‘LucidRook’ malware used in targeted attacks on NGOs, universities
  2. New VENOM phishing attacks steal senior executives’ Microsoft logins
  3. Healthcare IT solutions provider ChipSoft hit by ransomware attack
  4. Smart Slider updates hijacked to push malicious WordPress, Joomla versions
  5. When attackers already have the keys, MFA is just another door to open
  6. Webinar: From noise to signal – What threat actors are targeting next
  7. Google Rolls Out DBSC in Chrome 146 to Block Session Theft on Windows
  8. Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers
  9. EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallet Installs
  10. ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories

Top Stories


New ‘LucidRook’ malware used in targeted attacks on NGOs, universities

Source: BleepingComputer | Risk: High | Impacted: NGO IT environments, University networks, Email gateways, Endpoint devices

A new Lua-based malware, called LucidRook, is being used in spear-phishing campaigns targeting non-governmental organizations and universities in Taiwan.

Why it matters: New ‘LucidRook’ malware used in targeted attacks on NGOs, universities

Practitioner Perspective

NGOs and universities in Taiwan are currently being actively targeted by campaigns using the new LucidRook malware. This reflects a continued focus by well-resourced threat actors on sectors with soft perimeters and access to sensitive data. For defenders, this is a reminder that targeted phishing and bespoke malware are not limited to government targets, and your sector may now be in scope. Assess your exposure to spear-phishing and ensure behavioral controls can spot post-compromise activity typical for new toolsets. The top concern is rapid detection and containment after an initial phish succeeds.

Recommended Actions

  • Update threat intelligence feeds for LucidRook indicators
  • Conduct spear-phishing simulation targeting staff

New VENOM phishing attacks steal senior executives’ Microsoft logins

Source: BleepingComputer | Risk: High | Impacted: Executive Microsoft accounts, Corporate M365 tenants, Privileged user logins, Identity providers

Threat actors using a previously undocumented phishing-as-a-service (PhaaS) platform called “VENOM” are targeting credentials of C-suite executives across multiple industries.

Why it matters: New VENOM phishing attacks steal senior executives’ Microsoft logins

Practitioner Perspective

Phishing campaigns using the VENOM platform are zeroing in on C-suite and other high-value users. The targeting of executive credentials should be considered a material risk: it directly threatens business email, SaaS, and privileged access. These developments reinforce that standard phishing controls and off-the-shelf anti-phishing gateways are not sufficient for protecting VIP accounts. Security teams must assume phishing is getting through and proactively hunt for account misuse. The core question is whether you can detect and respond to executive account compromise before business impact.

Recommended Actions

  • Enable real-time alerting for VIP account logins from new locations/devices
  • Conduct targeted phishing awareness for executives

Healthcare IT solutions provider ChipSoft hit by ransomware attack

Source: BleepingComputer | Risk: High | Impacted: Healthcare software vendors, Patient portals, Hospital IT, Third-party SaaS providers

Dutch healthcare software vendor ChipSoft has been impacted by a ransomware attack that forced the company to take offline its website and digital services for patients and healthcare providers.

Why it matters: Healthcare IT solutions provider ChipSoft hit by ransomware attack

Practitioner Perspective

The ransomware attack affecting ChipSoft demonstrates the real operational disruption that can occur when a single IT provider goes offline. Healthcare organizations dependent on third-party vendors should take this as another warning that vendor outage equals immediate service impact. This continues a wider trend of threat actors hitting service providers to maximize downstream effect. Now is the time to validate incident response plans that account for vendor outages. The essential action is ensuring business continuity if a platform or vendor is suddenly unavailable.

Recommended Actions

  • Test business continuity and disaster recovery for vendor disruption
  • Inventory current vendor dependencies and access

Smart Slider updates hijacked to push malicious WordPress, Joomla versions

Source: BleepingComputer | Risk: High | Impacted: WordPress administrators, Joomla site operators, CMS plugin users, Web hosts

Hackers hijacked the update system for the Smart Slider 3 Pro plugin for WordPress and Joomla, and pushed a malicious version with multiple backdoors.

Why it matters: Smart Slider updates hijacked to push malicious WordPress, Joomla versions

Practitioner Perspective

The Smart Slider 3 Pro supply chain compromise highlights the risk of trusting plugin update infrastructure. Many WordPress and Joomla sites with this plugin may now unknowingly run malicious code due to update process tampering. This is not an isolated incident but part of a pattern where attackers exploit plugin ecosystems to reach downstream targets. Defenders can no longer assume official sources are always clean—every plugin or module is a potential delivery vehicle. Priority must be on rapid identification and remediation of compromised components.

Recommended Actions

  • Scan all sites for Smart Slider 3 Pro version 3.5.1.35
  • Compare plugin files with known-good hashes

When attackers already have the keys, MFA is just another door to open

Source: BleepingComputer | Risk: Medium | Impacted: Identity providers, Cloud authentication systems, Users with legacy MFA, Web apps with weak session controls

Stolen credentials turn authentication systems into the attack surface. Token shows how wearable biometric authentication verifies the user—not the session—blocking phishing relays and MFA bypass.

Why it matters: When attackers already have the keys, MFA is just another door to open

Practitioner Perspective

Attackers with valid credentials can often bypass multi-factor authentication, especially through session hijacking or MFA relay attacks. The narrative that MFA is a silver bullet for account security is dangerously outdated. Security teams need to focus on modern phishing-resistant authentication, user presence verification, and robust session management. If you rely on MFA alone, you may be blind to stealthy post-auth compromise. The critical question is how adversaries can exploit session and token handling in your environment.

Recommended Actions

  • Evaluate authentication workflows for session fixation and relay weaknesses
  • Implement phishing-resistant MFA (FIDO2, passkeys)

Webinar: From noise to signal – What threat actors are targeting next

Source: BleepingComputer | Risk: Medium | Impacted: Threat intelligence teams, SOC analysts, Security engineering, Incident response

Threat actors often signal their intentions before launching attacks, from dark web chatter to access-broker listings and credential requests. Join our upcoming webinar with Flare Systems to learn how to turn those early warning signs into proactive defensive action before an intrusion begins.

Why it matters: Threat actors often signal their intentions before launching attacks, from dark web chatter to access-broker listings and credential requests. Join our upcoming webinar with Flare Systems to learn how to turn those early warning signs

Practitioner Perspective

Threat actor intent regularly surfaces before exploitation—through dark web chatter, access broker activity, and early indicator signals. Too many teams wait for published CVEs or media attention before reacting, missing the proactive phase of defense. This webinar offers actionable advice for moving beyond reactive postures to threat-driven detection. If you aren’t already mining and triaging emerging threat signals, you’re leaving critical dwell time for attackers. The main takeaway: integrating threat intelligence earlier can be a multiplier for detection and response.

Recommended Actions

  • Subscribe to closed-source threat intel feeds or specialized platforms
  • Implement dark web monitoring for your org’s assets

Emerging Signals


Google Rolls Out DBSC in Chrome 146 to Block Session Theft on Windows

Source: The Hacker News | Risk: Medium | Impacted: Windows desktop fleets, Chrome browser users, Users exposed to infostealer malware, Organizations relying on web SSO

Google has made Device Bound Session Credentials (DBSC) generally available to all Windows users of its Chrome web browser, months after it began testing the security feature in open beta. The public availability is currently limited to Windows users on Chrome 146, with macOS expansion planned in an upcoming Chrome release. “This project represents a significant

Why it matters: Google has made Device Bound Session Credentials (DBSC) generally available to all Windows users of its Chrome web browser, months after it began testing the security feature in open beta. The public availability is currently limited to Windows users on

Practitioner Perspective

Google’s rollout of Device Bound Session Credentials (DBSC) in Chrome 146 for Windows targets malware-driven session cookie theft, a persistent infostealer technique. This represents a meaningful structural improvement but only benefits environments with updated installations and Windows endpoints. Defenders should recognize this is a material shift in browser security, but legacy and unmanaged devices will remain vulnerable. The top priority is accelerating deployment of updated Chrome versions to all supported devices.

Recommended Actions

  • Force-update Chrome to version 146 across managed Windows devices
  • Educate users on the value of browser updates

Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers

Source: The Hacker News | Risk: High | Impacted: WordPress and Joomla sites running Smart Slider 3 Pro, Website admins, Hosting providers, Digital marketing teams

Unknown threat actors have hijacked the update system for the Smart Slider 3 Pro plugin for WordPress and Joomla to push a poisoned version containing a backdoor. The incident impacts Smart Slider 3 Pro version 3.5.1.35 for WordPress, per WordPress security company Patchstack. Smart Slider 3 is a popular WordPress slider plugin with more than 800,000 active installations across its

Why it matters: Unknown threat actors have hijacked the update system for the Smart Slider 3 Pro plugin for WordPress and Joomla to push a poisoned version containing a backdoor. The incident impacts Smart Slider 3 Pro version

Practitioner Perspective

The compromise of the Smart Slider 3 Pro plugin update channel demonstrates the persistent weakness in CMS supply chains. Attackers backdoored a widely used plugin, exposing hundreds of thousands of sites to potential follow-on exploitation. This event underscores that automated plugin updates, once considered a best practice, can turn into mass compromise vectors if upstream code is breached. Defenders must stop treating vendor updates as inherently safe and implement additional validation and logging. Your first concern should be inventorying and remediating this plugin across your web-facing assets.

Recommended Actions

  • Identify deployments of Smart Slider 3 Pro and confirm plugin integrity
  • Patch or roll back to known clean plugin versions

EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallet Installs

Source: The Hacker News | Risk: Medium | Impacted: Android app developers, Cryptocurrency wallet app users, Mobile security teams, Customers using affected apps

Details have emerged about a now-patched security vulnerability in a widely used third-party Android software development kit (SDK) called EngageLab SDK that could have put millions of cryptocurrency wallet users at risk. “This flaw allows apps on the same device to bypass Android security sandbox and gain unauthorized access to private data,” the Microsoft Defender

Why it matters: Details have emerged about a now-patched security vulnerability in a widely used third-party Android software development kit (SDK) called EngageLab SDK that could have put millions of cryptocurrency wallet users at risk. “This flaw allows apps on the same

Practitioner Perspective

A now-patched vulnerability in the EngageLab SDK left millions of Android apps, including those handling cryptocurrency, open to sandbox escapes and unauthorized data access. Any organization distributing or relying on SDK-dependent Android apps needs to verify remediation. This is a case study in how supply chain vulnerabilities in third-party code can bypass core OS protections. Don’t trust that patching your own code is enough: you must hunt for exposure via all included SDKs, and keep monitoring vendors for post-patch exploitation.

Recommended Actions

  • Audit all Android apps for EngageLab SDK dependencies
  • Force update or remove vulnerable SDK versions from apps

ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories

Source: The Hacker News | Risk: Medium | Impacted: Systems with unpatched legacy vulnerabilities, Organizations relying on platform defaults, Environments with unmanaged assets

Thursday. Another week, another batch of things that probably should’ve been caught sooner but weren’t. This one’s got some range — old vulnerabilities getting new life, a few “why was that even possible” moments, attackers leaning on platforms and tools you’d normally trust without thinking twice. Quiet escalations more than loud zero-days, but the kind that matter more in

Why it matters: Thursday. Another week, another batch of things that probably should’ve been caught sooner but weren’t. This one’s got some range — old vulnerabilities getting new life, a few “why was that even possible” moments, attackers leaning on

Practitioner Perspective

This roundup illustrates how overlooked vulnerabilities and basic misconfigurations continue to fuel serious breaches, alongside novel attack techniques. The persistence of legacy RCE flaws and platform misuse should alarm defenders who assume attackers only chase zero-days. Make no assumptions about the age or obscurity of a bug: revisit vulnerability management with attackers’ incentives in mind. The lesson is clear: you must continually reevaluate your patching and controls or risk being caught out by ‘known’ weaknesses now weaponized at scale.

Recommended Actions

  • Review vulnerability backlog for aging CVEs
  • Reassess configurations of trusted platforms

Exploits & CVEs

No new high-confidence exploits or CVEs reported in the past 24 hours beyond the plugin and SDK supply chain stories already listed above.

Defensive Actions

  • Update threat intelligence feeds for LucidRook indicators
  • Conduct spear-phishing simulation targeting staff and privileged users
  • Hunt for suspicious DLL loads, lateral movement, and Lua/Rust-based artifacts on endpoints
  • Scan all sites for Smart Slider 3 Pro version 3.5.1.35 and compare plugin files with trusted hashes
  • Enable real-time alerting for VIP account logins from new locations or devices
  • Require phishing-resistant MFA for C-suite users
  • Test business continuity and disaster recovery for vendor disruption
  • Implement dark web monitoring and subscribe to specialized threat intel feeds
  • Force-update Chrome to version 146 across Windows endpoints and educate users on browser update value
  • Audit all Android apps for EngageLab SDK dependencies and remove or update vulnerable packages

What We’re Watching

  • Escalating supply chain attacks targeting web infrastructure plugins, especially WordPress and Joomla
  • Success of phishing-as-a-service targeting executives and emergence of new infostealer containment techniques
  • Concrete operational impacts of ransomware on healthcare vendors affecting patient services
  • Security feature rollouts in Chrome addressing session theft and infostealer risks
  • Fresh scrutiny on mobile SDK dependencies posing sandbox escape vulnerabilities in major app deployments
  • Continued trend of APTs targeting academia and NGOs with evolving custom malware


Categories: Cybersecurity Blog, Cybersecurity News

Tags: , , , , ,

Leave a Reply

Discover more from TECHMANIACS.com

Subscribe now to keep reading and get access to the full archive.

Continue reading