Hackers breach TrueConf to trojanize client installers with backdoors

2026-08-08T19:23:21Zcbec08a5acce91288e311e6076318173c8c476feccbc0eec23f00920ac7c4374
ClickFixMetabaseSQL injectionSharePointSpectre v2TrueConfactive exploitationbackdoorcloud securitycredential theftcritical infrastructurecryptocurrency theftdata breachdata theftextortioninfostealermacOSransomwareside-channel attacksocial engineeringsupply-chain compromisetrojanized installerszero-day

What happened

A BleepingComputer security feed reports active and emerging cyber threats, including exploitation of unpatched TrueConf and Metabase vulnerabilities, server and cloud breaches, trojanized installers, ransomware and extortion activity, macOS infostealers, social engineering, payment hijacking, and speculative-execution attacks. Several incidents involve confirmed exploitation, data theft, operational disruption, or compromise of sensitive credentials and accounts.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
cbec08a5acce91288e311e6076318173c8c476feccbc0eec23f00920ac7c4374
Enrichment time
2026-08-08T19:23:21Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.