LIVE · cybersecurity feed
Live wire
vulnerability

Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it

Ukrainian hacktivists exploiting the bugs, but TrueConf's reach stretches well beyond home turf

zeroday.news ·

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies patch two actively exploited vulnerabilities in TrueConf Server, a video conferencing platform developed in Russia. The flaws, identified as CVE-2026-72529 and CVE-2026-72530, were added to CISA's Known Exploited Vulnerabilities catalog on Thursday, indicating their use in real-world attacks. Federal agencies are required to apply the patches by September 10.

TrueConf, based in Moscow, offers on-premises video conferencing solutions, allowing organizations to host the server on their own infrastructure, including private networks. While the company's primary customer base is in Russia, it has a global user presence, including entities like Switzerland’s Department of Justice and Home Affairs and Istanbul Airport.

Security researchers have linked the exploitation of these vulnerabilities to Head Mare, a pro-Ukrainian hacktivist group. This group has previously targeted Russian organizations across various sectors, including transport, energy, electronics, IT, and software development. The latest campaign reportedly involved compromising TrueConf servers to distribute malware to meeting participants.

The two vulnerabilities, when chained together, allow an attacker to gain control of the underlying server. CVE-2026-72529 enables an unauthenticated attacker with network access to TCP port 4307, which TrueConf documentation states is open by default, to execute a malicious script. CVE-2026-72530 then allows the attacker to escape the isolated environment of the script and execute arbitrary code on the server.

In observed attacks, Head Mare exploited this access to install a web shell, move laterally within the victim's infrastructure, and obtain privileged access to the TrueConf database. Attackers then replaced the legitimate TrueConf Windows client installer on compromised servers with a trojanized version containing the PhantomCore backdoor.

This method of attack poses a risk not only to organizations directly running vulnerable TrueConf servers but also to employees who join conferences hosted by third parties. Such individuals could inadvertently download a compromised client from a hacked server belonging to a supplier or partner.

TrueConf released fixes for these vulnerabilities on June 18 in versions 5.3.9, 5.4.9, and 5.5.5. The company warned customers that failing to update could leave their conferencing systems exposed to attacks over the public internet. The flaws affect TrueConf Server releases dating back to 2022.

While exploitation requires network access to the vulnerable service, meaning servers confined to internal networks would not be directly reachable from the outside without an initial breach, the potential for malware distribution through compromised client installers highlights the broader risk.

vulnerabilitypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug

Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification. The post In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug appeared first on SecurityWeek.

security

Your Shredded Visa Card May Still Work at the Checkout

UMass Amherst researchers showed expired Visa contactless cards can make real purchases by exploiting an unsigned expiry field in Visa’s EMV kernel. Researchers at the University of Massachusetts Amherst demonstrated at USENIX Security 2026 in Baltimore that expired Visa contactless credit cards can complete real purchases, including transactions at live retail and grocery merchants, by […]

phishing

New SynkLoader malware pushed in Microsoft Teams phishing campaign

A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. [...]

ai

OWASP Flags Top AI Skill Risks in New Security Blueprint

The Open Worldwide Application Security Project has a brand-new top 10 security list tailored for the modern era, and it debuts a Universal Skill Format to add consistency and security to the AI add-ons.

ai

AI Is Learning to Write Genetic Code

This sort of research is both exciting and terrifying: The two models in question were told to generate complete genomes for a viable bacteriophage—a type of virus able to infect and replicate itself inside bacteria, destroying them from the inside. Using an existing bacteriophage as an example—ΦX174 (pronounced “fie-ex-1-7-4”), known for its ability to infect and destroy E. coli bacteria—the mode

nation-state

Former NSA Director Paul Nakasone Launches National Security Advisory Firm

The newly-formed Nakasone Group will counsel government leaders, corporations, prominent families, and other private clients confronting cybersecurity, geopolitical, and personal security risks. The post Former NSA Director Paul Nakasone Launches National Security Advisory Firm appeared first on SecurityWeek.