Cybersecurity briefing — 2026-04-02
Here's your PlainSec briefing for Thursday, April 2nd.
Active Dawn Zero-Day in Chrome Enables Sandbox Escape
UNC1069 Expands Node.js Supply Chain Attacks Beyond Axios
TrueConf Update Flaw Lets Attackers Run Malware on Isolated Endpoints
Drift Protocol Admin Key Compromise Enables $130M-$285M Crypto Theft
Active Cyber Intrusion Disrupts Hasbro Operations for Weeks
Attackers Exploit Vite Dev Server Feature to Steal Files
Mercor AI Confirms Data Theft via LiteLLM Supply Chain Breach
Tiered CrystalX RAT Bundles Spyware, Stealer, Prankware
Cambodia Extradites Key Crypto Scam Leader to China Amid Crackdown
REF1695 campaign update
Federal citizen lists to restrict mail ballots; data mismatch risk
Researchers Observe Sub-One-Hour Ransomware Attacks
Open-Source AI Runtime Breach Disrupts Vendor Trust and Operations
Chinese APT TA416 Resumes Stealthy Espionage on European Diplomats
Kernel-Level BPFDoor Variants Evade Detection in Telecom Infrastructure
Mass CERT-UA Impersonation Sends AGEWHEEZE RAT via Password-Protected ZIP
Qilin ransomware campaign update
UAT-10608: Inside a large-scale automated credential harvesting operation targeting web applications
An overview of ransomware threats in Japan in 2025 and early detection insights from Qilin cases
Stolen Supply-Chain Secrets Fuel Cloud Intrusions and Extortion
Authenticated Admin Access Enables Root File Write in Cisco Nexus Dashboard Insights
Cisco SSM On-Prem Has Both Authenticated Privilege Escalation and Unauthenticated Root RCE
VenomStealer campaign update
WhatsApp VBS Drops Renamed Windows Tools, MSI Backdoors
Encrypted Nexus Dashboard Backups Leak Credentials, Enable Root Access
Third-Party Vendor Breach Exposes Nissan Dealership Data, Not Nissan Systems
Security update
Cybersecurity briefing — 2026-04-02
Here's your PlainSec briefing for Thursday, April 2nd.
Active Dawn Zero-Day in Chrome Enables Sandbox Escape
UNC1069 Expands Node.js Supply Chain Attacks Beyond Axios
TrueConf Update Flaw Lets Attackers Run Malware on Isolated Endpoints
Drift Protocol Admin Key Compromise Enables $130M-$285M Crypto Theft
Active Cyber Intrusion Disrupts Hasbro Operations for Weeks
Attackers Exploit Vite Dev Server Feature to Steal Files
Mercor AI Confirms Data Theft via LiteLLM Supply Chain Breach
Tiered CrystalX RAT Bundles Spyware, Stealer, Prankware
Cambodia Extradites Key Crypto Scam Leader to China Amid Crackdown
REF1695 campaign update
Federal citizen lists to restrict mail ballots; data mismatch risk
Researchers Observe Sub-One-Hour Ransomware Attacks
Open-Source AI Runtime Breach Disrupts Vendor Trust and Operations
Chinese APT TA416 Resumes Stealthy Espionage on European Diplomats
Kernel-Level BPFDoor Variants Evade Detection in Telecom Infrastructure
Mass CERT-UA Impersonation Sends AGEWHEEZE RAT via Password-Protected ZIP
Qilin ransomware campaign update
UAT-10608: Inside a large-scale automated credential harvesting operation targeting web applications
An overview of ransomware threats in Japan in 2025 and early detection insights from Qilin cases
Stolen Supply-Chain Secrets Fuel Cloud Intrusions and Extortion
Authenticated Admin Access Enables Root File Write in Cisco Nexus Dashboard Insights
Cisco SSM On-Prem Has Both Authenticated Privilege Escalation and Unauthenticated Root RCE
VenomStealer campaign update
WhatsApp VBS Drops Renamed Windows Tools, MSI Backdoors
Encrypted Nexus Dashboard Backups Leak Credentials, Enable Root Access
Third-Party Vendor Breach Exposes Nissan Dealership Data, Not Nissan Systems
Security update