
Coverage: Last 24 hours
Today’s Highlights
Today’s news centers on targeted malware campaigns, phishing attacks against executives, critical plugin supply chain compromises, and browser security improvements. Defenders should focus on detection and response for advanced persistent threats, phishing targeting privileged users, and incidents exploiting trust in third-party software dependencies.
Table of Contents
- New ‘LucidRook’ malware used in targeted attacks on NGOs, universities
- New VENOM phishing attacks steal senior executives’ Microsoft logins
- Healthcare IT solutions provider ChipSoft hit by ransomware attack
- Smart Slider updates hijacked to push malicious WordPress, Joomla versions
- When attackers already have the keys, MFA is just another door to open
- Webinar: From noise to signal – What threat actors are targeting next
- Google Rolls Out DBSC in Chrome 146 to Block Session Theft on Windows
- Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers
- EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallet Installs
- ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories
Top Stories
New ‘LucidRook’ malware used in targeted attacks on NGOs, universities
Source: BleepingComputer | Risk: High | Impacted: NGO IT environments, University networks, Email gateways, Endpoint devices
A new Lua-based malware, called LucidRook, is being used in spear-phishing campaigns targeting non-governmental organizations and universities in Taiwan.
Why it matters: New ‘LucidRook’ malware used in targeted attacks on NGOs, universities
Practitioner Perspective
NGOs and universities in Taiwan are currently being actively targeted by campaigns using the new LucidRook malware. This reflects a continued focus by well-resourced threat actors on sectors with soft perimeters and access to sensitive data. For defenders, this is a reminder that targeted phishing and bespoke malware are not limited to government targets, and your sector may now be in scope. Assess your exposure to spear-phishing and ensure behavioral controls can spot post-compromise activity typical for new toolsets. The top concern is rapid detection and containment after an initial phish succeeds.
Recommended Actions
- Update threat intelligence feeds for LucidRook indicators
- Conduct spear-phishing simulation targeting staff
New VENOM phishing attacks steal senior executives’ Microsoft logins
Source: BleepingComputer | Risk: High | Impacted: Executive Microsoft accounts, Corporate M365 tenants, Privileged user logins, Identity providers
Threat actors using a previously undocumented phishing-as-a-service (PhaaS) platform called “VENOM” are targeting credentials of C-suite executives across multiple industries.
Why it matters: New VENOM phishing attacks steal senior executives’ Microsoft logins
Practitioner Perspective
Phishing campaigns using the VENOM platform are zeroing in on C-suite and other high-value users. The targeting of executive credentials should be considered a material risk: it directly threatens business email, SaaS, and privileged access. These developments reinforce that standard phishing controls and off-the-shelf anti-phishing gateways are not sufficient for protecting VIP accounts. Security teams must assume phishing is getting through and proactively hunt for account misuse. The core question is whether you can detect and respond to executive account compromise before business impact.
Recommended Actions
- Enable real-time alerting for VIP account logins from new locations/devices
- Conduct targeted phishing awareness for executives
Healthcare IT solutions provider ChipSoft hit by ransomware attack
Source: BleepingComputer | Risk: High | Impacted: Healthcare software vendors, Patient portals, Hospital IT, Third-party SaaS providers
Dutch healthcare software vendor ChipSoft has been impacted by a ransomware attack that forced the company to take offline its website and digital services for patients and healthcare providers.
Why it matters: Healthcare IT solutions provider ChipSoft hit by ransomware attack
Practitioner Perspective
The ransomware attack affecting ChipSoft demonstrates the real operational disruption that can occur when a single IT provider goes offline. Healthcare organizations dependent on third-party vendors should take this as another warning that vendor outage equals immediate service impact. This continues a wider trend of threat actors hitting service providers to maximize downstream effect. Now is the time to validate incident response plans that account for vendor outages. The essential action is ensuring business continuity if a platform or vendor is suddenly unavailable.
Recommended Actions
- Test business continuity and disaster recovery for vendor disruption
- Inventory current vendor dependencies and access
Smart Slider updates hijacked to push malicious WordPress, Joomla versions
Source: BleepingComputer | Risk: High | Impacted: WordPress administrators, Joomla site operators, CMS plugin users, Web hosts
Hackers hijacked the update system for the Smart Slider 3 Pro plugin for WordPress and Joomla, and pushed a malicious version with multiple backdoors.
Why it matters: Smart Slider updates hijacked to push malicious WordPress, Joomla versions
Practitioner Perspective
The Smart Slider 3 Pro supply chain compromise highlights the risk of trusting plugin update infrastructure. Many WordPress and Joomla sites with this plugin may now unknowingly run malicious code due to update process tampering. This is not an isolated incident but part of a pattern where attackers exploit plugin ecosystems to reach downstream targets. Defenders can no longer assume official sources are always clean—every plugin or module is a potential delivery vehicle. Priority must be on rapid identification and remediation of compromised components.
Recommended Actions
- Scan all sites for Smart Slider 3 Pro version 3.5.1.35
- Compare plugin files with known-good hashes
When attackers already have the keys, MFA is just another door to open
Source: BleepingComputer | Risk: Medium | Impacted: Identity providers, Cloud authentication systems, Users with legacy MFA, Web apps with weak session controls
Stolen credentials turn authentication systems into the attack surface. Token shows how wearable biometric authentication verifies the user—not the session—blocking phishing relays and MFA bypass.
Why it matters: When attackers already have the keys, MFA is just another door to open
Practitioner Perspective
Attackers with valid credentials can often bypass multi-factor authentication, especially through session hijacking or MFA relay attacks. The narrative that MFA is a silver bullet for account security is dangerously outdated. Security teams need to focus on modern phishing-resistant authentication, user presence verification, and robust session management. If you rely on MFA alone, you may be blind to stealthy post-auth compromise. The critical question is how adversaries can exploit session and token handling in your environment.
Recommended Actions
- Evaluate authentication workflows for session fixation and relay weaknesses
- Implement phishing-resistant MFA (FIDO2, passkeys)
Webinar: From noise to signal – What threat actors are targeting next
Source: BleepingComputer | Risk: Medium | Impacted: Threat intelligence teams, SOC analysts, Security engineering, Incident response
Threat actors often signal their intentions before launching attacks, from dark web chatter to access-broker listings and credential requests. Join our upcoming webinar with Flare Systems to learn how to turn those early warning signs into proactive defensive action before an intrusion begins.
Why it matters: Threat actors often signal their intentions before launching attacks, from dark web chatter to access-broker listings and credential requests. Join our upcoming webinar with Flare Systems to learn how to turn those early warning signs
Practitioner Perspective
Threat actor intent regularly surfaces before exploitation—through dark web chatter, access broker activity, and early indicator signals. Too many teams wait for published CVEs or media attention before reacting, missing the proactive phase of defense. This webinar offers actionable advice for moving beyond reactive postures to threat-driven detection. If you aren’t already mining and triaging emerging threat signals, you’re leaving critical dwell time for attackers. The main takeaway: integrating threat intelligence earlier can be a multiplier for detection and response.
Recommended Actions
- Subscribe to closed-source threat intel feeds or specialized platforms
- Implement dark web monitoring for your org’s assets
Emerging Signals
Google Rolls Out DBSC in Chrome 146 to Block Session Theft on Windows
Source: The Hacker News | Risk: Medium | Impacted: Windows desktop fleets, Chrome browser users, Users exposed to infostealer malware, Organizations relying on web SSO
Google has made Device Bound Session Credentials (DBSC) generally available to all Windows users of its Chrome web browser, months after it began testing the security feature in open beta. The public availability is currently limited to Windows users on Chrome 146, with macOS expansion planned in an upcoming Chrome release. “This project represents a significant
Why it matters: Google has made Device Bound Session Credentials (DBSC) generally available to all Windows users of its Chrome web browser, months after it began testing the security feature in open beta. The public availability is currently limited to Windows users on
Practitioner Perspective
Google’s rollout of Device Bound Session Credentials (DBSC) in Chrome 146 for Windows targets malware-driven session cookie theft, a persistent infostealer technique. This represents a meaningful structural improvement but only benefits environments with updated installations and Windows endpoints. Defenders should recognize this is a material shift in browser security, but legacy and unmanaged devices will remain vulnerable. The top priority is accelerating deployment of updated Chrome versions to all supported devices.
Recommended Actions
- Force-update Chrome to version 146 across managed Windows devices
- Educate users on the value of browser updates
Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers
Source: The Hacker News | Risk: High | Impacted: WordPress and Joomla sites running Smart Slider 3 Pro, Website admins, Hosting providers, Digital marketing teams
Unknown threat actors have hijacked the update system for the Smart Slider 3 Pro plugin for WordPress and Joomla to push a poisoned version containing a backdoor. The incident impacts Smart Slider 3 Pro version 3.5.1.35 for WordPress, per WordPress security company Patchstack. Smart Slider 3 is a popular WordPress slider plugin with more than 800,000 active installations across its
Why it matters: Unknown threat actors have hijacked the update system for the Smart Slider 3 Pro plugin for WordPress and Joomla to push a poisoned version containing a backdoor. The incident impacts Smart Slider 3 Pro version
Practitioner Perspective
The compromise of the Smart Slider 3 Pro plugin update channel demonstrates the persistent weakness in CMS supply chains. Attackers backdoored a widely used plugin, exposing hundreds of thousands of sites to potential follow-on exploitation. This event underscores that automated plugin updates, once considered a best practice, can turn into mass compromise vectors if upstream code is breached. Defenders must stop treating vendor updates as inherently safe and implement additional validation and logging. Your first concern should be inventorying and remediating this plugin across your web-facing assets.
Recommended Actions
- Identify deployments of Smart Slider 3 Pro and confirm plugin integrity
- Patch or roll back to known clean plugin versions
EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallet Installs
Source: The Hacker News | Risk: Medium | Impacted: Android app developers, Cryptocurrency wallet app users, Mobile security teams, Customers using affected apps
Details have emerged about a now-patched security vulnerability in a widely used third-party Android software development kit (SDK) called EngageLab SDK that could have put millions of cryptocurrency wallet users at risk. “This flaw allows apps on the same device to bypass Android security sandbox and gain unauthorized access to private data,” the Microsoft Defender
Why it matters: Details have emerged about a now-patched security vulnerability in a widely used third-party Android software development kit (SDK) called EngageLab SDK that could have put millions of cryptocurrency wallet users at risk. “This flaw allows apps on the same
Practitioner Perspective
A now-patched vulnerability in the EngageLab SDK left millions of Android apps, including those handling cryptocurrency, open to sandbox escapes and unauthorized data access. Any organization distributing or relying on SDK-dependent Android apps needs to verify remediation. This is a case study in how supply chain vulnerabilities in third-party code can bypass core OS protections. Don’t trust that patching your own code is enough: you must hunt for exposure via all included SDKs, and keep monitoring vendors for post-patch exploitation.
Recommended Actions
- Audit all Android apps for EngageLab SDK dependencies
- Force update or remove vulnerable SDK versions from apps
ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories
Source: The Hacker News | Risk: Medium | Impacted: Systems with unpatched legacy vulnerabilities, Organizations relying on platform defaults, Environments with unmanaged assets
Thursday. Another week, another batch of things that probably should’ve been caught sooner but weren’t. This one’s got some range — old vulnerabilities getting new life, a few “why was that even possible” moments, attackers leaning on platforms and tools you’d normally trust without thinking twice. Quiet escalations more than loud zero-days, but the kind that matter more in
Why it matters: Thursday. Another week, another batch of things that probably should’ve been caught sooner but weren’t. This one’s got some range — old vulnerabilities getting new life, a few “why was that even possible” moments, attackers leaning on
Practitioner Perspective
This roundup illustrates how overlooked vulnerabilities and basic misconfigurations continue to fuel serious breaches, alongside novel attack techniques. The persistence of legacy RCE flaws and platform misuse should alarm defenders who assume attackers only chase zero-days. Make no assumptions about the age or obscurity of a bug: revisit vulnerability management with attackers’ incentives in mind. The lesson is clear: you must continually reevaluate your patching and controls or risk being caught out by ‘known’ weaknesses now weaponized at scale.
Recommended Actions
- Review vulnerability backlog for aging CVEs
- Reassess configurations of trusted platforms
Exploits & CVEs
No new high-confidence exploits or CVEs reported in the past 24 hours beyond the plugin and SDK supply chain stories already listed above.
Defensive Actions
- Update threat intelligence feeds for LucidRook indicators
- Conduct spear-phishing simulation targeting staff and privileged users
- Hunt for suspicious DLL loads, lateral movement, and Lua/Rust-based artifacts on endpoints
- Scan all sites for Smart Slider 3 Pro version 3.5.1.35 and compare plugin files with trusted hashes
- Enable real-time alerting for VIP account logins from new locations or devices
- Require phishing-resistant MFA for C-suite users
- Test business continuity and disaster recovery for vendor disruption
- Implement dark web monitoring and subscribe to specialized threat intel feeds
- Force-update Chrome to version 146 across Windows endpoints and educate users on browser update value
- Audit all Android apps for EngageLab SDK dependencies and remove or update vulnerable packages
What We’re Watching
- Escalating supply chain attacks targeting web infrastructure plugins, especially WordPress and Joomla
- Success of phishing-as-a-service targeting executives and emergence of new infostealer containment techniques
- Concrete operational impacts of ransomware on healthcare vendors affecting patient services
- Security feature rollouts in Chrome addressing session theft and infostealer risks
- Fresh scrutiny on mobile SDK dependencies posing sandbox escape vulnerabilities in major app deployments
- Continued trend of APTs targeting academia and NGOs with evolving custom malware
Categories: Cybersecurity Blog, Cybersecurity News
Leave a Reply