📰 DAILY THREAT BRIEFING
Thursday, April 2, 2026
12 News Items
THN · BleepingComputer · Krebs · Dark Reading · SANS

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of April 2, 2026.

  1. New CrystalRAT malware adds RAT, stealer and prankware features
    — Bleeping Computer

    A new malware-as-a-service called CrystalRAT is being promoted on Telegram, offering remote access, data theft, keylogging, and clipboard hi…
  2. Apple expands iOS 18 updates to more iPhones to block DarkSword attacks
    — Bleeping Computer

    Apple has now made it possible for more iPhones still running iOS 18 to receive security updates that protect against the actively exploited…
  3. Hackers exploit TrueConf zero-day to push malicious software updates
    — Bleeping Computer

    Hackers have targeted TrueConf conference servers in attacks that exploit a zero-day vulnerability, allowing them to execute arbitrary files…
  4. Malicious Script That Gets Rid of ADS, (Wed, Apr 1st)
    — SANS ISC

    Today, most malware are called “fileless” because they try to reduce their footprint on the infected computer file…
  5. New EvilTokens service fuels Microsoft device code phishing attacks
    — Bleeping Computer

    A new malicious kit called EvilTokens integrates device code phishing capabilities, allowing attackers to hijack Microsoft accounts and prov…
  6. LatAm's Self-Taught Cyber Talent Overlooked Amid Cyberattack Glut
    — Dark Reading

    A newly released study exclusively shared with Dark Reading details the unique circumstances that make up Latin America's labor pool, and wh…
  7. Cyberattacks Intensify Pressure on Latin American Governments
    — Dark Reading

    Cyber threats across Latin America are increasingly targeting government systems, from disruptive attacks in Puerto Rico to a surge of probe…
  8. CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails
    — The Hacker News

    The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new phishing campaign in which the cybersecurity agency…
  9. Venom Stealer MaaS Platform Commoditizes ClickFix Attacks
    — Dark Reading

    A new service on the cybercrime market provides automated capabilities to create persistent information-stealing social engineering attacks.
  10. Microsoft Warns of WhatsApp-Delivered VBS Malware Hijacking Windows via UAC Bypass
    — The Hacker News

    Microsoft is calling attention to a new campaign that has leveraged WhatsApp messages to distribute malicious Visual Basic Script (VBS) file…
  11. TeamPCP Supply Chain Campaign: Update 005 – First Confirmed Victim Disclosure, Post-Compromise Cloud Enumeration Documented, and Axios Attribution Narrows, (Wed, Apr 1st)
    — SANS ISC

    This is the fifth update to the TeamPCP supply chain campaign threat intelligence report, "When the Security Scanner Became the Weapon" (v3.…
  12. Block the Prompt, Not the Work: The End of "Doctor No"
    — The Hacker News

    There is a character that keeps appearing in enterprise security departments, and most CISOs know exactly who that is. It doesn’t build. I…

Generated by HiveNet.ai Threat Intelligence Platform · April 2, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC