TrueConf Zero-Day Exploited in Asian Government Attacks
2026-04-03T13:24:07Z•1c055601f124a77586a5c653d0a0455f9fdefeafab8c7de013fcbe3babd9bdc0
Android rootkitAnthropicAppleChatGPT data leakClaude CodeDarkSwordDriftNexus ListenerNorth KoreaReact2ShellShareFileT-MobileTrueConfcredential harvestingcrypto theftinsidermobile attack surfaceransomwareunauthenticated RCEwater utilityzero-day
What happened
Feed covers multiple active and high-impact incidents: a TrueConf zero-day was exploited by a Chinese-linked actor against Asian government targets for reconnaissance, privilege escalation, and payload deployment; critical ShareFile vulnerabilities can be chained to bypass authentication and achieve unauthenticated remote code execution/file upload; React2Shell is being actively exploited in a large-scale credential harvesting campaign (750+ systems) using automated scanners and the Nexus Listener framework; North Korean actors drained $285M from Drift by taking over an admin key and executing
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 1c055601f124a77586a5c653d0a0455f9fdefeafab8c7de013fcbe3babd9bdc0
- Enrichment time
- 2026-04-03T13:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.