Cyber Security Week in Review: April 3, 2026
In brief: Google patches Chrome zero-day, Chinese hackers exploit zero-day flaw in TrueConf, and more.
In brief: Google patches Chrome zero-day, Chinese hackers exploit zero-day flaw in TrueConf, and more.
While some of TA416’s techniques, tactics and procedures remained unchanged, Proofpoint observed the group modifying its infection chains.
The campaign combines social engineering with “living-off-the-land” techniques.
Google didn’t disclose any additional details regarding the nature of exploitation.
As part of the breach, multiple AWS access keys were stolen and later used for unauthorized activity across a limited number of Cisco cloud accounts.
Attackers leveraged the update channel of TrueConf to deliver malware, more specifically a payload linked to the Havoc C&C framework.
The hackers hijacked the npm account of the library's developer and inserted a malicious dependency into the package configuration.
He now faces up to 10 years in prison on a computer fraud charge and up to 20 years if convicted of money laundering.
The investigation began when the researchers examined activity linked to the Stately Taurus group that leveraged USB-based malware called USBFect, aka HIUPAN.
The leak reportedly includes personal messages dating back to 2010 and 2019, as well as images allegedly taken from Patel’s account.
Showing elements 151 - 160