North Korea-aligned state-sponsored hacking group ScarCruft has compromised a video game platform in a supply chain attack, infecting its components with a backdoor called BirdCall. The malware is believed to target ethnic Koreans living in China. Unlike previous versions of the backdoor that focused on Windows systems, this supply chain attack has expanded the malware’s reach to additional platforms.
Weaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited via Debug API
A critical security vulnerability in Weaver E-cology, an enterprise office automation and collaboration platform, is being actively exploited in the wild. The vulnerability CVE-2026-22679 has a CVSS score of 9.8 and allows unauthenticated remote code execution in Weaver E-cology versions prior to 20260312. The flaw is located in the debug API endpoint.
Microsoft Details Phishing Campaign Targeting 35,000 Users Across 26 Countries
Microsoft has disclosed a large-scale credential theft campaign that used code of conduct-themed emails and legitimate email services to direct users to attacker-controlled domains for stealing authentication tokens. The campaign, observed between April 14 and 16, 2026, targeted more than 35,000 users from over 13,000 organizations across 26 countries.
Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools
A phishing campaign tracked as VENOMOUS#HELPER has targeted over 80 organizations since at least April 2025, primarily in the U.S., according to Securonix. The attackers use legitimate Remote Monitoring and Management software, including SimpleHelp and ScreenConnect, to gain persistent remote access to compromised systems.
Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass
Progress Software has released updates to address two security flaws in MOVEit Automation, including a critical vulnerability that could enable authentication bypass. MOVEit Automation is a server-based managed file transfer solution used by enterprises to schedule and automate file movement workflows without requiring custom scripts.
⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More
This week saw multiple critical security developments. While organizations were addressing previous alerts, attackers exploited new vulnerabilities in control systems, kernel implementations, and open-source platforms. The threat landscape has evolved to include persistent access to SaaS environments, unauthorized code commits, and expanding attack capabilities.
Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in India and Russia
The China-based cybercrime group Silver Fox, also known as Monarch, SwimSnake, The Great Thief of Valley, UTG-Q-1000, and Void Arachne, has been linked to a campaign targeting organizations in Russia and India using a new malware called ABCDoor. The campaign employed phishing emails impersonating the Income Tax Department of India, beginning in December 2025.
Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in India and Russia
The China-based cybercrime group Silver Fox, also known as Monarch, SwimSnake, The Great Thief of Valley, UTG-Q-1000, and Void Arachne, has been linked to a campaign targeting organizations in Russia and India using new malware called ABCDoor. The campaign used phishing emails impersonating the Income Tax Department of India beginning in December 2025.
