logo

MSP cybersecurity news digest, April 20, 2026

ID: eadca55a-3323-5168-a07d-918644e59b8e

STIX ID: report--eadca55a-3323-5168-a07d-918644e59b8e

Feed Name: TRU Security by Acronis

Threat Score
80/100

Date Published: 2026-04-20

Date Updated: 2026-07-24

...
...

This briefing covers several active, high-risk cyber campaigns: Payouts King ransomware operators use hidden QEMU VMs as reverse-SSH backdoors to evade host detection and stage credential collection; the AgingFly campaign uses phishing and staged payloads to target local governments, hospitals, and defense-related personnel in Ukraine; a signed-adware operation deployed payloads that disabled antivirus on ~23,500 hosts across 124 countries; over 100 malicious Chrome Web Store extensions stole OAuth tokens and session data for account takeovers and backdoors; and targeted token/session theft attacks bypass MFA in Microsoft 365, emphasizing a shift toward post-authentication abuse and defense-evasion techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.