Check Point Research[verified]@_CPResearch_Active Exploitation
A Chinese‑nexus actor leveraged CVE‑2026‑3502 to compromise Southeast Asian government targets using DLL sideloading and UAC bypass. No patch, PoC, or detailed vulnerability classification is provided.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
The tweet announces ongoing exploitation of CVE-2026-3502, a zero‑day in TrueConf, by a Chinese APT targeting Southeast Asian government agencies, using missing integrity checks to push malicious updates.
kokumօtօ[verified]@__kokumotoActive Exploitation
The post details confirmed in‑the‑wild use of the TrueConf CVE‑2026‑3502 zero‑day, where attackers exploited the update mechanism to deliver malware to Southeast Asian government agencies.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
CVE-2026-3502 is actively exploited by Chinese APT actors using a detailed attack chain involving DLL sideloading, UAC bypass, and Havoc payloads, with no patch or PoC mentioned.
piyokango[verified]@piyokangoActive Exploitation
The post reports that CVE‑2026‑3502, a critical integrity‑verification flaw in TrueConf’s client, has been added to CISA’s Known Exploited Vulnerabilities list and has seen in‑the‑wild exploitation, but no patch or functional exploitation code has been disclosed.
Misbar | مسبار[verified]@MisbarSecActive Exploitation
CISA lists CVE-2026-3502 for TrueConf as a KEV, confirming it is being exploited in the wild and urging users to apply security updates promptly.
Criminal IP[verified]@CriminalIP_USGeneral
The digest lists multiple CVEs with technical details but offers no PoCs, exploit code, active exploitation evidence, or patch information, leading to a general classification.
Criminal IP Japan[verified]@CriminalIP_JPGeneral
The digest lists several CVEs and related threats, but provides no PoC, exploitation details, patches, or technical specifics.