米サイバーセキュリティインフラストラクチャセキュリティ庁(CISA)は、「TrueConf Server」に判明した2件の脆弱性が悪用されているとして注意を呼びかけた。いずれもリモートから攻撃を受けるおそれがある。
同製品は、TrueConfが提供するビデオ会議やコミュニケーション機能を提供するサーバソフトウェア。同庁は現地時間2026年8月20日、「悪用が確認された脆弱性カタログ(KEV)」へ「TrueConf Server」に関する2件の脆弱性「CVE-2026-72529」「CVE-2026-72530」...
米サイバーセキュリティインフラストラクチャセキュリティ庁(CISA)は、「TrueConf Server」に判明した2件の脆弱性が悪用されているとして注意を呼びかけた。いずれもリモートから攻撃を受けるおそれがある。
同製品は、TrueConfが提供するビデオ会議やコミュニケーション機能を提供するサーバソフトウェア。同庁は現地時間2026年8月20日、「悪用が確認された脆弱性カタログ(KEV)」へ「TrueConf Server」に関する2件の脆弱性「CVE-2026-72529」「CVE-2026-72530」...
Release Date August 20, 2026
CVE-2026-72529 TrueConf Server Missing Authentication for Critical Function Vulnerability
CVE-2026-72530 TrueConf Server Code Injection Vulnerability
Release Date August 20, 2026
CVE-2026-72529 TrueConf Server Missing Authentication for Critical Function Vulnerability
CVE-2026-72530 TrueConf Server Code Injection Vulnerability
セキュアなオンプレミス型ビデオ会議プラットフォームであるTrueConfは、専用の企業サーバーを介してクライアントアプリケーションを接続するために、スケーラブルビデオコーディング(SVC)を利用しています。
2022年以降のすべてのTrueConf Serverバージョンには、CVE-2026-72529およびCVE-2026-72530として追跡されている2つの重大なバグが含まれており、攻撃者が任意のコードを実行できる可能性があります。
これら2つの脆弱性は、ポート4307/TCP経由でTrue...
セキュアなオンプレミス型ビデオ会議プラットフォームであるTrueConfは、専用の企業サーバーを介してクライアントアプリケーションを接続するために、スケーラブルビデオコーディング(SVC)を利用しています。
2022年以降のすべてのTrueConf Serverバージョンには、CVE-2026-72529およびCVE-2026-72530として追跡されている2つの重大なバグが含まれており、攻撃者が任意のコードを実行できる可能性があります。
これら2つの脆弱性は、ポート4307/TCP経由でTrue...
米国サイバーセキュリティ・インフラストラクチャセキュリティ庁(CISA)は、 既知の悪用された脆弱性(KEV)カタログに以下の脆弱性を追加しました。
CVE-2026-72529 (CVSSスコア9.3)TrueConfサーバーの重要機能に対する認証機能の欠落の脆弱性
CVE-2026-72530 (CVSSスコア9.5)TrueConfサーバーのコードインジェクション脆弱性
TrueConf Serverは、Tru...
米国サイバーセキュリティ・インフラストラクチャセキュリティ庁(CISA)は、 既知の悪用された脆弱性(KEV)カタログに以下の脆弱性を追加しました。
CVE-2026-72529 (CVSSスコア9.3)TrueConfサーバーの重要機能に対する認証機能の欠落の脆弱性
CVE-2026-72530 (CVSSスコア9.5)TrueConfサーバーのコードインジェクション脆弱性
TrueConf Serverは、Tru...
Head Mare APTグループは、パッチが適用されていないTrueConf Serverインスタンスを介したサプライチェーン侵害に関与しており、これによりPhantomCoreマルウェアがビデオ会議の参加者に配信された。
カスペルスキーの研究者たちは、ロシアの組織に対する攻撃を調査する中で、この活動を特定した。攻撃者は、侵害したサーバー上に正規のTrueConfクライアントインストーラーをホストし、会議アプリケーションとともにリモートアクセスマルウェアを密かに展開していた
Head Mare APTグループは、パッチが適用されていないTrueConf Serverインスタンスを介したサプライチェーン侵害に関与しており、これによりPhantomCoreマルウェアがビデオ会議の参加者に配信された。
カスペルスキーの研究者たちは、ロシアの組織に対する攻撃を調査する中で、この活動を特定した。攻撃者は、侵害したサーバー上に正規のTrueConfクライアントインストーラーをホストし、会議アプリケーションとともにリモートアクセスマルウェアを密かに展開していた
米国サイバーセキュリティ・インフラストラクチャセキュリティ庁(CISA)は、米国の連邦機関に対し、TrueConf Serverというセルフホスト型通信プラットフォームに存在する、現在悪用されている2つの脆弱性へのパッチ適用を優先するよう命じた。
TrueConf Serverは、安全な企業向けメッセージングおよびビデオ会議のために設計されており、ZoomやMicrosoft Teamsのようなクラウドベースのソフトウェアとは異なり、組織のローカルネットワーク(LAN)内で動作します。
米国サイバーセキュリティ・インフラストラクチャセキュリティ庁(CISA)は、米国の連邦機関に対し、TrueConf Serverというセルフホスト型通信プラットフォームに存在する、現在悪用されている2つの脆弱性へのパッチ適用を優先するよう命じた。
TrueConf Serverは、安全な企業向けメッセージングおよびビデオ会議のために設計されており、ZoomやMicrosoft Teamsのようなクラウドベースのソフトウェアとは異なり、組織のローカルネットワーク(LAN)内で動作します。
Patch FortiClient EMS. Verify TrueConf integrity. Audit npm dependencies. Rotate secrets.
#CyberSecurity #InfoSec
Patch FortiClient EMS. Verify TrueConf integrity. Audit npm dependencies. Rotate secrets.
#CyberSecurity #InfoSec
cybersecuritynews.com
cybersecuritynews.com
cybersecuritynews.com
cybersecuritynews.com
Patch FortiClient EMS. Verify TrueConf integrity. Audit npm dependencies. Rotate secrets.
#CyberSecurity #InfoSec
Patch FortiClient EMS. Verify TrueConf integrity. Audit npm dependencies. Rotate secrets.
#CyberSecurity #InfoSec
cybersecuritynews.com
cybersecuritynews.com
🔗 https://www.theregister.com/patches/2026/08/21/homeland-security-cybercops-say-patch-trueconf-russias-zoom-if-youre-using-it/5291156
#Tech #Enterprise
🔗 https://www.theregister.com/patches/2026/08/21/homeland-security-cybercops-say-patch-trueconf-russias-zoom-if-youre-using-it/5291156
#Tech #Enterprise
AI scripts → Siemens PLC memory/ladder logic.
GitLab → unauthenticated, exploited in minutes.
TrueConf → Head Mare, PhantomCore malware.
ShieldBreak → Defender patch bypassed. No fix.
🇬🇧 diesec.com/2026/08/top-...
#Cybersecurity #DIESEC
AI scripts → Siemens PLC memory/ladder logic.
GitLab → unauthenticated, exploited in minutes.
TrueConf → Head Mare, PhantomCore malware.
ShieldBreak → Defender patch bypassed. No fix.
🇬🇧 diesec.com/2026/08/top-...
#Cybersecurity #DIESEC
Patch FortiClient EMS. Verify TrueConf integrity. Audit npm dependencies. Rotate secrets.
#CyberSecurity #InfoSec
Patch FortiClient EMS. Verify TrueConf integrity. Audit npm dependencies. Rotate secrets.
#CyberSecurity #InfoSec
cybersecuritynews.com
cybersecuritynews.com
#ThreatIntel #CyberSecurity #SOC #CISA #VulnerabilityManagement #DetectionEngineering
#ThreatIntel #CyberSecurity #SOC #CISA #VulnerabilityManagement #DetectionEngineering
https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-trueconf-server-flaws/
#cybersecurity #infosec
https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-trueconf-server-flaws/
#cybersecurity #infosec
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More...
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More...
Read full story
Read full story
https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-trueconf-server-flaws/
https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-trueconf-server-flaws/