SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 91

2026-04-06T02:51:55Zf0ba960b9218f228b62165fb6a40dd08ea14f58e0cc241206b6400b68c40b3d1
CVE-2026-3502axioscryptocurrency-heistcrystalx-ratdata-breachdrifthandalahasbroinfiniti-stealerknown-exploited-vulnerabilitiesmaasmacos-infostealernorth-koreanpmpsk-windqilinransomwaresupply-chain-attackteamPCPtrueconf

What happened

Security Affairs roundup covering multiple high-impact incidents: CISA added TrueConf client flaw CVE-2026-3502 (CVSS 7.8) to its Known Exploited Vulnerabilities list; CERT-EU attributed a European Commission cloud breach exposing data from ~30 EU entities to TeamPCP; a sophisticated $285M crypto heist (likely North Korea‑linked) drained funds from Drift. Other notable items include Qilin ransomware claiming a hack of German party Die Linke, an npm/axios supply‑chain compromise, the emergence of CrystalX RAT as a MaaS offering, a new macOS infostealer (“Infiniti Stealer”), a .cmd mail‑deliever

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
f0ba960b9218f228b62165fb6a40dd08ea14f58e0cc241206b6400b68c40b3d1
Enrichment time
2026-04-06T02:51:55Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 91 · Baitaphish