Drift loses $280 million as hackers seize Security Council powers
2026-04-02T19:23:32Z•df74bdbb614437182a12ace667e29df164183259ca6639eddc5704ab6ca4e165
cisco-imccredential-theftcrystalratdarksworddata-wipingdevice-code-phishingeviltokensf5-big-iphandalamail-fraudmalwarenetwork-exposurenovoicephishingpre-auth-exploitprogress-sharefileproxy-evasionratrceresidential-proxiesstealersupply-chaintrueconfzero-day
What happened
A batch of BleepingComputer reports (Apr 1–2, 2026) describes widespread active exploitation, new malware, and evasive attacker infrastructure. Notable items include large-scale protocol compromise at Drift ($280M loss), active zero-days and pre-auth RCE chains (TrueConf zero-day; Progress ShareFile), thousands of exposed F5 BIG-IP APM instances under RCE attack, a critical Cisco IMC authentication bypass, and a destructive data‑wiping incident at Stryker attributed to Handala. The feed also highlights growing operational tradecraft — residential proxies evading IP reputation checks, mail-drop
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- df74bdbb614437182a12ace667e29df164183259ca6639eddc5704ab6ca4e165
- Enrichment time
- 2026-04-02T19:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.