- TruffleHogTool used by attackers to scan for AWS secrets and validate credentials via STS calls
ThreatNoir Weekend Brief — April 4
Afternoon Review in IT Security — April 4, 2026
The afternoon of April 4, 2026, brings critical security developments across multiple fronts, from European government infrastructure breaches to vulnerabilities in critical power systems. Organizations worldwide face mounting pressure to address active exploitation threats and supply chain risks that continue to reshape the threat landscape.
European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack
The European Commission has confirmed a significant data breach connected to a Trivy supply chain attack, with hackers stealing over 300GB of data from the Commission's AWS environment. The compromised data includes personal information, highlighting the serious impact of supply chain vulnerabilities on high-profile government institutions. This incident underscores how attackers continue to exploit widely-used development tools to gain access to sensitive infrastructure. Source: European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack
Hackers Are Posting the Claude Code Leak With Bonus Malware
Threat actors are actively distributing leaked Claude source code alongside malware payloads, marking a dangerous convergence of code theft and malware distribution. The incident is part of a broader pattern in which attackers are weaponizing stolen source code to amplify their campaigns. Additionally, the FBI has warned that a recent hack of its wiretap tools poses a national security risk, while attackers have stolen Cisco source code as part of an ongoing supply chain hacking spree. Source: Hackers Are Posting the Claude Code Leak With Bonus Malware
Critical Denial of Service Vulnerabilities in Siemens SICAM 8 Products
Multiple critical vulnerabilities have been identified in Siemens SICAM 8 products, affecting critical infrastructure worldwide. CVE-2026-27663 is a denial-of-service vulnerability in which remote operation mode is susceptible to resource exhaustion when subjected to high volumes of requests, potentially requiring a reset or reboot to restore functionality. CVE-2026-27664 is an out-of-bounds write vulnerability triggered by specially crafted XML inputs that could allow unauthenticated attackers to crash the service and cause denial-of-service conditions. Affected products include CPCI85 Central Processing/Communication, RTUM85 RTU Base, and SICORE Base system, all with versions below 26.10. Siemens has released updates and strongly recommends all operators apply the security updates immediately. Source: Siemens SICAM 8 Products
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added CVE-2026-3502, a TrueConf Client vulnerability involving download of code without integrity checks, to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. This vulnerability represents a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Under Binding Operational Directive 22-01, Federal Civilian Executive Branch agencies are required to remediate identified vulnerabilities by the specified due date. CISA urges all organizations to prioritize timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practices. Source: CISA Adds One Known Exploited Vulnerability to Catalog
As the afternoon concludes, security teams face an urgent agenda: patching critical infrastructure vulnerabilities, investigating supply chain compromises, and remediating actively exploited flaws. The convergence of government breaches, critical system vulnerabilities, and weaponized code leaks signals a particularly active threat environment requiring immediate defensive action across all organizational levels.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- infostealerMalware embedded in Claude Code repositories posted on GitHub by threat actors
- Resource exhaustion DoS in CPCI85 and RTUM85 via high-volume requests
- Out-of-bounds write DoS in CPCI85 and SICORE via malicious XML parsing
- TrueConf Client Download of Code Without Integrity Check Vulnerability - actively exploited