LIVE · cybersecurity feed
Live wire
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataCVE-2026-8037 · CISA Adds Progress LoadMaster Command Injection Flaw to KEV CatalogSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It AllAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to AttackersNew CSS Attacks Can Break Webmail Defenses to Steal Passwords and TokensCVE-2023-38646 · Metabase Zero-Day Exploited in Wild Allows Admin Access Without AuthenticationCVE-2026-18577 · N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and PersistCVE-2026-8037 · Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit AttemptsLiving off the coding agent: Two tales of tunnels and LaunchAgents
breach

Hackers breach TrueConf to trojanize client installers with backdoors

The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. [...]

zeroday.news ·

Hackers are exploiting vulnerabilities in TrueConf video conferencing servers to distribute malicious client installers containing backdoors, according to research from Kaspersky. The attacks, attributed to a group named Head Mare, leverage two specific flaws, internally tracked as KLCERT-26-057 and KLCERT-26-058, to achieve arbitrary code execution and privilege escalation, ultimately leading to the deployment of PhantomCore and PhantomGraph backdoors.

TrueConf, a video conferencing solution popular in Russia, particularly within government and enterprise sectors, is often used as an on-premise alternative to Western platforms. Kaspersky researchers identified the campaign in July, noting that Head Mare exploits TCP port 4307, which is open by default on TrueConf servers, to connect without authentication.

The attack chain involves using KLCERT-26-057 to execute a malicious script within TrueConf's isolated environment, followed by KLCERT-26-058 to escape the sandbox and run commands on the underlying operating system. Attackers then escalate privileges to NT AUTHORITY\SYSTEM and replace the `\public\js\locale.php` file with a web shell, establishing persistent remote access.

This web shell is used to gather sensitive information, access the TrueConf database, and replace the legitimate TrueConf Client installer with a trojanized version containing the PhantomCore backdoor. When users connect to a compromised local TrueConf server, they receive this non-digitally signed, malicious client installer as an update. Kaspersky warns that even organizations not directly using a TrueConf server can be affected if their employees connect to compromised third-party TrueConf servers for meetings and download the infected packages.

In addition to PhantomCore, Head Mare deploys PhantomGraph, a separate backdoor comprising two DLL files, `SysExcSvc.dll` and `SysReadSvc.dll`. PhantomGraph communicates via a Microsoft OneDrive account, executing commands and returning results. Observed activities include dumping the memory of the Local Security Authority Subsystem Service (LSASS) process to exfiltrate credentials, performing reconnaissance commands like `hostname` and `whoami`, and initiating reverse SSH tunnels.

Kaspersky is currently observing multiple active Head Mare campaigns targeting Russian organizations across various sectors, including instrumentation, electronics, transportation, energy, IT, and software development. The threat actor employs several initial access methods, including phishing, exploiting public-facing web servers, and gaining access through contractors.

The vulnerabilities exploited by Head Mare affect TrueConf Server versions 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and older releases. TrueConf released patches for these flaws on June 18, in versions 5.3.9, 5.4.9, and 5.5.5.

This incident follows a report from April 2026 by CheckPoint Research, which detailed a separate campaign, "Operation True Chaos," targeting a zero-day arbitrary file execution flaw in TrueConf, identified as CVE-2026-3502. That campaign also involved compromising users via trojanized client updates and was tentatively attributed to Chinese threat actors utilizing the Havoc implant.

breachvulnerabilitymalwarepatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
breachcritical

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data. The post Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data appeared first on SecurityWeek.

ai

Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default

Researchers scour social media to measure developer concerns about AI coding tools

vulnerabilityhigh

Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data

Attackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims. Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against Metabase Cloud before anyone on the defense side knew it existed. The company’s own […]

surveillance

Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed

Flock Safety, a company known for its public safety cameras, reportedly pitched a plan to utilize dashcams from rideshare and delivery vehicles to collect license plate data. This initiative, which did not proceed, would have involved a partnership with Nexar, a dashcam manufacturer, and potentially involved drivers without their knowledge. Separately, a former Flock employee alleged the company provided direct camera access to ICE and CBP through a pilot program, contradicting internal statements.

email securityhigh

Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All

Security researchers Cory Solovewicz and Mike Sheward have inadvertently created honeypots by purchasing domains like noreply.us and deleteduser.com. Organizations are mistakenly sending sensitive data, including personal information, company secrets, and system credentials, to these domains, believing they are unmonitored. Both researchers are now working to notify affected entities and raise awareness about this widespread misconfiguration, highlighting the potential for malicious actors to exploit such vulnerabilities.

atlassianhigh

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Two security firms have identified vulnerabilities in Atlassian's Rovo assistant that could allow attackers to exfiltrate data from Jira and Confluence. One vulnerability, dubbed RovoBlast by Varonis Threat Labs, allowed attackers to trick Rovo into sending data to an external server via a malicious link. Atlassian has confirmed this issue is fixed server-side. The second vulnerability, found by PromptArmor, involved injecting malicious instructions into content Rovo processes, enabling data exfiltration without explicit user approval. The status of this second vulnerability remains unconfirmed after its initial disclosure.