#TrueConf
Suspected Chinese APT leverages a TrueConf zero-day

research.checkpoint.com/2026/operati...
March 31, 2026 at 6:50 PM
The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors.
Hackers breach TrueConf to trojanize client installers with backdoors
The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors.
www.bleepingcomputer.com
August 8, 2026 at 2:18 PM
Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it
Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it
Ukrainian hacktivists exploiting the bugs, but TrueConf's reach stretches well beyond home turf
www.theregister.com
August 21, 2026 at 4:31 PM
Hackers have targeted TrueConf conference servers in attacks that exploit a zero-day vulnerability, allowing them to execute arbitrary files on all connected endpoints.
Hackers exploit TrueConf zero-day to push malicious software updates
Hackers have targeted TrueConf conference servers in attacks that exploit a zero-day vulnerability, allowing them to execute arbitrary files on all connected endpoints.
www.bleepingcomputer.com
April 1, 2026 at 9:36 PM
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform.
CISA orders feds to patch actively exploited TrueConf Server flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform.
www.bleepingcomputer.com
August 21, 2026 at 12:25 PM
-Perforce servers widely exposed on the internet
-The Hormuz scams are here
-Malware reports on The Gentlemen, Kyber, TwizAdmin, NGate, PhantomCLR, Gh0st RAT, Formbook, FudCrypt
-Ukrainian APT goes after TrueConf
-EU sanctions hit the Kremlin disinfo peddler
-Major KEV update
April 22, 2026 at 10:07 AM
PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Networks thehackernews.com/2026/04/phan...
PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Networks
PhantomCore exploited three TrueConf flaws since September 2025, enabling remote access and lateral movement across Russian networks.
thehackernews.com
April 29, 2026 at 4:42 AM
April 3, 2026 at 4:47 AM
Head Mare exploited TrueConf flaws to swap legit client installers with trojanized versions delivering PhantomCore and PhantomGraph backdoors, enabling credential theft and remote access. #TrueConf #Russia #HeadMare
Hackers breach TrueConf to trojanize client installers with backdoors
Head Mare has been exploiting unpatched TrueConf server vulnerabilities to replace legitimate client installers with trojanized versions that deliver the PhantomCore and PhantomGraph backdoors. Kaspersky says the campaign targets Russian organizations and can impact users even through compromised third-party TrueConf servers, enabling credential theft, reconnaissance, and persistent remote access. #HeadMare #TrueConf #PhantomCore #PhantomGraph
www.hendryadrian.com
August 8, 2026 at 2:45 PM
Hackers breach TrueConf to trojanize client installers with backdoors

huntaegis.com
August 8, 2026 at 2:52 PM
U.S. CISA adds a flaw in TrueConf Client to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in TrueConf Client to its Known Exploited Vulnerabilities catalog The U.S. Cybersecurity and Infrastructure Securit…
#hackernews #news
U.S. CISA adds a flaw in TrueConf Client to its Known Exploited Vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in TrueConf Client to its Known Exploited Vulnerabilities catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in TrueConf Client, tracked as CVE-2026-3502 (CVSS score of 7.8), to its Known Exploited Vulnerabilities (KEV) catalog. TrueConf is a videoconferencing platform often used in secure, offline […]
securityaffairs.com
April 6, 2026 at 12:54 AM
CISA adds critical TrueConf vulnerability (CVE-2026-3502) to KEV catalog amid active exploitation. Organizations urged to patch immediately to prevent potential breaches. #CyberSecurity #CISA #TrueConf #Vulnerability Link: thedailytechfeed.com/cisa-urges-a...
April 6, 2026 at 3:24 PM
-Head Mare attacks TrueConf servers
-Kimi escapes test environment
-N-able issues additional zero-day patch
-New Kemp LoadMaster attacks
-RovoBlast, SCTPhantom, KerberLoss, and ResetNightmare vulns
-New NatJack attack
-New CSS attack steals your inbox and passwords
August 10, 2026 at 8:03 AM
Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it
Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it
Ukrainian hacktivists exploiting the bugs, but TrueConf's reach stretches well beyond home turf
www.theregister.com
August 21, 2026 at 5:11 PM
Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to
deliver PhantomCore and PhantomGraph to video conference participants
securelist.com/tr/head-mare...
Head Mare delivers PhantomCore and PhantomGraph backdoors via an unpatched TrueConf server
Kaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver the PhantomCore and PhantomGraph backdoors to target systems by exploiting vulner...
securelist.com
August 12, 2026 at 11:08 AM
米国サイバーセキュリティ・インフラストラクチャセキュリティ庁(CISA)は、TrueConf Serverの脆弱性を既知の悪用された脆弱性カタログに追加した。

米国サイバーセキュリティ・インフラストラクチャセキュリティ庁(CISA)は、 既知の悪用された脆弱性(KEV)カタログに以下の脆弱性を追加しました。

CVE-2026-72529 (CVSSスコア9.3)TrueConfサーバーの重要機能に対する認証機能の欠落の脆弱性
CVE-2026-72530 (CVSSスコア9.5)TrueConfサーバーのコードインジェクション脆弱性

TrueConf Serverは、Tru...
U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog.
securityaffairs.com
September 23, 2026 at 9:33 PM
Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it

www.theregister.com/patches/2026...

#Cybersecurity #CISA
Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it
Ukrainian hacktivists exploiting the bugs, but TrueConf's reach stretches well beyond home turf
www.theregister.com
August 21, 2026 at 4:58 PM
📢 Opération TrueChaos : exploitation d'un 0-day TrueConf contre des gouvernements d'Asie du Sud-Est
📝 ## 🔍 Contexte

Publié le 31 ma…
https://cyberveille.ch/posts/2026-04-03-operation-truechaos-exploitation-d-un-0-day-trueconf-contre-des-gouvernements-d-asie-du-sud-est/ #Amaranth_Dragon #Cyberveille
April 3, 2026 at 6:30 PM
📢 Opération TrueChaos : zero-day dans TrueConf exploité contre des gouvernements en Asie du Sud-Est
📝 ## 🔍 Contexte

Publié le 30 mars…
https://cyberveille.ch/posts/2026-04-02-operation-truechaos-zero-day-dans-trueconf-exploite-contre-des-gouvernements-en-asie-du-sud-est/ #CVE_2026_3502 #Cyberveille
April 2, 2026 at 8:30 PM
米当局、「TrueConf Server」の脆弱性2件を悪用リストへ追加

米サイバーセキュリティインフラストラクチャセキュリティ庁(CISA)は、「TrueConf Server」に判明した2件の脆弱性が悪用されているとして注意を呼びかけた。いずれもリモートから攻撃を受けるおそれがある。

同製品は、TrueConfが提供するビデオ会議やコミュニケーション機能を提供するサーバソフトウェア。同庁は現地時間2026年8月20日、「悪用が確認された脆弱性カタログ(KEV)」へ「TrueConf Server」に関する2件の脆弱性「CVE-2026-72529」「CVE-2026-72530」...
【セキュリティ ニュース】米当局、「TrueConf Server」の脆弱性2件を悪用リストへ追加(1ページ目 / 全1ページ):Security NEXT
米サイバーセキュリティインフラストラクチャセキュリティ庁(CISA)は、「TrueConf Server」に判明した2件の脆弱性が悪用されているとして注意を呼びかけた。いずれもリモートから攻撃を受けるおそれがある。 :Security NEXT
www.security-next.com
September 23, 2026 at 9:51 PM
¿Qué es WebRTC?

«WebRTC (Web Real Time Communications) es un estándar que permite la comunicación de redes entre pares en tiempo real y el intercambio de datos multimedia en navegadores».

Vía: @trueconf

trueconf.com/es-es/webrtc...
August 10, 2025 at 7:24 PM