Ukrainian hacktivists exploiting the bugs, but TrueConf's reach stretches well beyond home turf

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies patch two actively exploited vulnerabilities in TrueConf Server, a video conferencing platform developed in Russia. The flaws, identified as CVE-2026-72529 and CVE-2026-72530, were added to CISA's Known Exploited Vulnerabilities catalog on Thursday, indicating their use in real-world attacks. Federal agencies are required to apply the patches by September 10.
TrueConf, based in Moscow, offers on-premises video conferencing solutions, allowing organizations to host the server on their own infrastructure, including private networks. While the company's primary customer base is in Russia, it has a global user presence, including entities like Switzerland’s Department of Justice and Home Affairs and Istanbul Airport.
Security researchers have linked the exploitation of these vulnerabilities to Head Mare, a pro-Ukrainian hacktivist group. This group has previously targeted Russian organizations across various sectors, including transport, energy, electronics, IT, and software development. The latest campaign reportedly involved compromising TrueConf servers to distribute malware to meeting participants.
The two vulnerabilities, when chained together, allow an attacker to gain control of the underlying server. CVE-2026-72529 enables an unauthenticated attacker with network access to TCP port 4307, which TrueConf documentation states is open by default, to execute a malicious script. CVE-2026-72530 then allows the attacker to escape the isolated environment of the script and execute arbitrary code on the server.
In observed attacks, Head Mare exploited this access to install a web shell, move laterally within the victim's infrastructure, and obtain privileged access to the TrueConf database. Attackers then replaced the legitimate TrueConf Windows client installer on compromised servers with a trojanized version containing the PhantomCore backdoor.
This method of attack poses a risk not only to organizations directly running vulnerable TrueConf servers but also to employees who join conferences hosted by third parties. Such individuals could inadvertently download a compromised client from a hacked server belonging to a supplier or partner.
TrueConf released fixes for these vulnerabilities on June 18 in versions 5.3.9, 5.4.9, and 5.5.5. The company warned customers that failing to update could leave their conferencing systems exposed to attacks over the public internet. The flaws affect TrueConf Server releases dating back to 2022.
While exploitation requires network access to the vulnerable service, meaning servers confined to internal networks would not be directly reachable from the outside without an initial breach, the potential for malware distribution through compromised client installers highlights the broader risk.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.