Hackers breach TrueConf to trojanize client installers with backdoors

2026-08-09T01:23:22Zd9eff099be60b972c94f4a9ea1eaf7dc637ea44e85defc9bcd6e1f0f46d918d3
ClickFixMetabaseSQL-injectionSharePointTrueConfactive-exploitationbackdoorbusiness-email-compromisecloud-securitycritical-infrastructurecryptocurrency-theftdata-theftextortionfinancial-sectorgovernmenthealthcareinfostealermacOSransomwareside-channel-attacksocial-engineeringsupply-chain-compromisethreat-intelligencetrojanized-installerszero-day

What happened

BleepingComputer security news digest covering active exploitation, supply-chain compromise, data theft, ransomware, infostealers, extortion, cloud and SharePoint breaches, side-channel research, and cyberattacks against financial, government, healthcare, and critical-infrastructure organizations. The most urgent items include trojanized TrueConf installers, a Metabase SQL injection zero-day, macOS cryptocurrency infostealer campaigns, and exploitation of SharePoint vulnerabilities.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
d9eff099be60b972c94f4a9ea1eaf7dc637ea44e85defc9bcd6e1f0f46d918d3
Enrichment time
2026-08-09T01:23:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.