📰 DAILY THREAT BRIEFING
Friday, April 10, 2026
12 News Items
THN · BleepingComputer · Krebs · Dark Reading · SANS

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of April 10, 2026.

  1. New ‘LucidRook’ malware used in targeted attacks on NGOs, universities
    — Bleeping Computer

    A new Lua-based malware, called LucidRook, is being used in spear-phishing campaigns targeting non-governmental organizations and universiti…
  2. New VENOM phishing attacks steal senior executives' Microsoft logins
    — Bleeping Computer

    Threat actors using a previously undocumented phishing-as-a-service (PhaaS) platform called "VENOM" are targeting credentials of C-suite exe…
  3. Russia's 'Fancy Bear' APT Continues Its Global Onslaught
    — Dark Reading

    Victims don't need to match the cybercrime group's technical sophistication, experts say. But patching and some form of zero trust are now n…
  4. 'BlueHammer' Windows Zero-Day Exploit Signals Microsoft Bug Disclosure Issues
    — Dark Reading

    Under the alias 'Chaotic Eclipse,' a researcher released a PoC exploit for a zero-day flaw that allows for system takeover by a local user, …
  5. Healthcare IT solutions provider ChipSoft hit by ransomware attack
    — Bleeping Computer

    Dutch healthcare software vendor ChipSoft has been impacted by a ransomware attack that forced the company to take offline its website and d…
  6. Google Chrome adds infostealer protection against session cookie theft
    — Bleeping Computer

    Google has rolled out Device Bound Session Credentials (DBSC) protection in Chrome 146 for Windows, designed to block info-stealing malware …
  7. Do Ceasefires Slow Cyberattacks? History Suggests Not
    — Dark Reading

    The cybersecurity community is waiting with bated breath to see if Iranian hackers will honor a ceasefire that doesn't actually name or dire…
  8. EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets
    — The Hacker News

  9. UAT-10362 Targets Taiwanese NGOs with LucidRook Malware in Spear-Phishing Campaigns
    — The Hacker News

    A previously undocumented threat cluster dubbed UAT-10362 has been attributed to spear-phishing campaigns targeting Taiwanese non-governmen…
  10. ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories
    — The Hacker News

    Thursday. Another week, another batch of things that probably should've been caught sooner but weren't. This one's got some range — old …
  11. The Hidden Security Risks of Shadow AI in Enterprises
    — The Hacker News

    As AI tools become more accessible, employees are adopting them without formal approval from IT and security teams. While these tools may …
  12. ISC Stormcast For Thursday, April 9th, 2026 https://isc.sans.edu/podcastdetail/9886, (Thu, Apr 9th)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Generated by HiveNet.ai Threat Intelligence Platform · April 10, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC