MSP cybersecurity news digest, April 20, 2026
ID: eadca55a-3323-5168-a07d-918644e59b8e
STIX ID: report--eadca55a-3323-5168-a07d-918644e59b8e
Feed Name: TRU Security by Acronis
This briefing covers several active, high-risk cyber campaigns: Payouts King ransomware operators use hidden QEMU VMs as reverse-SSH backdoors to evade host detection and stage credential collection; the AgingFly campaign uses phishing and staged payloads to target local governments, hospitals, and defense-related personnel in Ukraine; a signed-adware operation deployed payloads that disabled antivirus on ~23,500 hosts across 124 countries; over 100 malicious Chrome Web Store extensions stole OAuth tokens and session data for account takeovers and backdoors; and targeted token/session theft attacks bypass MFA in Microsoft 365, emphasizing a shift toward post-authentication abuse and defense-evasion techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
