Six percent of organizations around the world were compromised with the FakeUpdates malware, also known as SocGholish, making it the most prevalent malicious payload in April, Hackread reports.
BleepingComputer reports that attacks with the ClickFix social engineering technique have been deployed by Pakistan-linked threat operation APT36, also known as Transparent Tribe, against both Windows and Linux systems.
Researchers have uncovered significant updates to OtterCookie, a cross-platform malware tied to the North Korean-aligned Contagious Interview campaign, according to The Hacker News.
BleepingComputer reports that between April 12 and April 16, 2025, the website of iClicker, a widely used student engagement platform, was compromised in a social engineering scheme known as a ClickFix attack.