TrueConf Zero-Day Exploited in Asian Government Attacks

2026-04-03T13:24:07Z1c055601f124a77586a5c653d0a0455f9fdefeafab8c7de013fcbe3babd9bdc0
Android rootkitAnthropicAppleChatGPT data leakClaude CodeDarkSwordDriftNexus ListenerNorth KoreaReact2ShellShareFileT-MobileTrueConfcredential harvestingcrypto theftinsidermobile attack surfaceransomwareunauthenticated RCEwater utilityzero-day

What happened

Feed covers multiple active and high-impact incidents: a TrueConf zero-day was exploited by a Chinese-linked actor against Asian government targets for reconnaissance, privilege escalation, and payload deployment; critical ShareFile vulnerabilities can be chained to bypass authentication and achieve unauthenticated remote code execution/file upload; React2Shell is being actively exploited in a large-scale credential harvesting campaign (750+ systems) using automated scanners and the Nexus Listener framework; North Korean actors drained $285M from Drift by taking over an admin key and executing

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
1c055601f124a77586a5c653d0a0455f9fdefeafab8c7de013fcbe3babd9bdc0
Enrichment time
2026-04-03T13:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.