Cybersecurity briefing — 2026-04-03
Here's your PlainSec briefing for Thursday, April 3rd.
Cloud Account Takeover After Trivy Supply-Chain Compromise
Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts, Steal Credentials
TrueConf Update Flaw Lets Attackers Reach Isolated Government Networks
Active Dawn Zero-Day in Chrome Enables Sandbox Escape
New Progress ShareFile flaws can be chained in pre-auth RCE attacks
F5 BIG-IP APM Flaw Reclassified as Critical RCE with Active Exploitation
Google Cloud Linux Kernel Flaws Enable Privilege Escalation on Container Nodes
FCC Targets Voice Providers for Routing Scam Calls via Dormant Accounts
UNC1069 activity affects axios (npm package)
Cisco Security Advisory: Cisco Integrated Management Controller Authentication Bypass Vulnerability
Java Deserialization RCE in Hitachi Energy Ellipse Reporting Component
Cisco IMC Command Injection Lets Read-Only Users Execute as Root
Attackers Exploit Vite Dev Server Feature to Steal Files
Qilin Ransomware Targets German Political Party with Data Theft and Extortion
Telehealth giant Hims & Hers says its customer support system was hacked
TeamPCP Compromises LiteLLM PyPI Package, Steals Credentials
State-Backed Hackers Target Personal Messaging Apps to Bypass Corporate Controls
Siemens SICAM 8 Firmware Flaws Cause Denial of Service via Resource Exhaustion
Akira activity affects SonicWall VPN appliances
REF1695 campaign update
Cybersecurity briefing — 2026-04-03
Here's your PlainSec briefing for Thursday, April 3rd.
Cloud Account Takeover After Trivy Supply-Chain Compromise
Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts, Steal Credentials
TrueConf Update Flaw Lets Attackers Reach Isolated Government Networks
Active Dawn Zero-Day in Chrome Enables Sandbox Escape
New Progress ShareFile flaws can be chained in pre-auth RCE attacks
F5 BIG-IP APM Flaw Reclassified as Critical RCE with Active Exploitation
Google Cloud Linux Kernel Flaws Enable Privilege Escalation on Container Nodes
FCC Targets Voice Providers for Routing Scam Calls via Dormant Accounts
UNC1069 activity affects axios (npm package)
Cisco Security Advisory: Cisco Integrated Management Controller Authentication Bypass Vulnerability
Java Deserialization RCE in Hitachi Energy Ellipse Reporting Component
Cisco IMC Command Injection Lets Read-Only Users Execute as Root
Attackers Exploit Vite Dev Server Feature to Steal Files
Qilin Ransomware Targets German Political Party with Data Theft and Extortion
Telehealth giant Hims & Hers says its customer support system was hacked
TeamPCP Compromises LiteLLM PyPI Package, Steals Credentials
State-Backed Hackers Target Personal Messaging Apps to Bypass Corporate Controls
Siemens SICAM 8 Firmware Flaws Cause Denial of Service via Resource Exhaustion
Akira activity affects SonicWall VPN appliances
REF1695 campaign update