#TrueConf
米当局、「TrueConf Server」の脆弱性2件を悪用リストへ追加

米サイバーセキュリティインフラストラクチャセキュリティ庁(CISA)は、「TrueConf Server」に判明した2件の脆弱性が悪用されているとして注意を呼びかけた。いずれもリモートから攻撃を受けるおそれがある。

同製品は、TrueConfが提供するビデオ会議やコミュニケーション機能を提供するサーバソフトウェア。同庁は現地時間2026年8月20日、「悪用が確認された脆弱性カタログ(KEV)」へ「TrueConf Server」に関する2件の脆弱性「CVE-2026-72529」「CVE-2026-72530」...
【セキュリティ ニュース】米当局、「TrueConf Server」の脆弱性2件を悪用リストへ追加(1ページ目 / 全1ページ):Security NEXT
米サイバーセキュリティインフラストラクチャセキュリティ庁(CISA)は、「TrueConf Server」に判明した2件の脆弱性が悪用されているとして注意を呼びかけた。いずれもリモートから攻撃を受けるおそれがある。 :Security NEXT
www.security-next.com
September 23, 2026 at 9:51 PM
CISA Adds Two Known Exploited Vulnerabilities to Catalog
Release Date August 20, 2026

CVE-2026-72529 TrueConf Server Missing Authentication for Critical Function Vulnerability
CVE-2026-72530 TrueConf Server Code Injection Vulnerability
CISA Adds Two Known Exploited Vulnerabilities to Catalog | CISA
An official website of the United States government
www.cisa.gov
September 23, 2026 at 9:51 PM
CISAは、悪用されたTrueConfの脆弱性に対する即時パッチ適用を強く推奨する。

セキュアなオンプレミス型ビデオ会議プラットフォームであるTrueConfは、専用の企業サーバーを介してクライアントアプリケーションを接続するために、スケーラブルビデオコーディング(SVC)を利用しています。

2022年以降のすべてのTrueConf Serverバージョンには、CVE-2026-72529およびCVE-2026-72530として追跡されている2つの重大なバグが含まれており、攻撃者が任意のコードを実行できる可能性があります。

これら2つの脆弱性は、ポート4307/TCP経由でTrue...
CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities
Head Mare hacktivist group exploiting critical TrueConf vulnerabilities CVE-2026-72529 and CVE-2026-72530 to deploy PhantomCore malware.
www.securityweek.com
September 23, 2026 at 9:40 PM
米国サイバーセキュリティ・インフラストラクチャセキュリティ庁(CISA)は、TrueConf Serverの脆弱性を既知の悪用された脆弱性カタログに追加した。

米国サイバーセキュリティ・インフラストラクチャセキュリティ庁(CISA)は、 既知の悪用された脆弱性(KEV)カタログに以下の脆弱性を追加しました。

CVE-2026-72529 (CVSSスコア9.3)TrueConfサーバーの重要機能に対する認証機能の欠落の脆弱性
CVE-2026-72530 (CVSSスコア9.5)TrueConfサーバーのコードインジェクション脆弱性

TrueConf Serverは、Tru...
U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog.
securityaffairs.com
September 23, 2026 at 9:33 PM
Head Mare APTがTrueConfサーバーのRCE脆弱性を悪用し、PhantomCoreマルウェアを配信

Head Mare APTグループは、パッチが適用されていないTrueConf Serverインスタンスを介したサプライチェーン侵害に関与しており、これによりPhantomCoreマルウェアがビデオ会議の参加者に配信された。

カスペルスキーの研究者たちは、ロシアの組織に対する攻撃を調査する中で、この活動を特定した。攻撃者は、侵害したサーバー上に正規のTrueConfクライアントインストーラーをホストし、会議アプリケーションとともにリモートアクセスマルウェアを密かに展開していた
Head Mare APT Exploits TrueConf Server RCE Flaws to Deliver PhantomCore Malware
The Head Mare APT group has been linked to a supply chain compromise involving unpatched TrueConf Server instances, which enabled the delivery of PhantomCore malware to video conference participants.
gbhackers.com
September 23, 2026 at 9:28 PM
CISAは、悪用されているTrueConf Serverの脆弱性を修正するよう連邦政府に命令した。

米国サイバーセキュリティ・インフラストラクチャセキュリティ庁(CISA)は、米国の連邦機関に対し、TrueConf Serverというセルフホスト型通信プラットフォームに存在する、現在悪用されている2つの脆弱性へのパッチ適用を優先するよう命じた。

TrueConf Serverは、安全な企業向けメッセージングおよびビデオ会議のために設計されており、ZoomやMicrosoft Teamsのようなクラウドベースのソフトウェアとは異なり、組織のローカルネットワーク(LAN)内で動作します。
CISA orders feds to patch actively exploited TrueConf Server flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communic...
www.bleepingcomputer.com
September 23, 2026 at 9:02 PM
Delphiレガシーコード改善術:「動いているから触れない」からの脱却。壊さずに進化させるリファクタリングとモダン化の技術, オンプレミスで実現する安全な社内コミュニケーション TrueConf Server構築・運用の教科書: ゼロからわかる企業内ビデオ会議・チャット完全入門ガイド・構築・運用実践マニュアル, 計算待ち時間をゼロにするMATLABプログラミング術: 遅いコードを劇的に変える最適化の技術 ― ベクトル化からGPU・MEX活用まで高速化実践入門 <美山 ゆい> が、Kindleストアで販売開始されました。
計算待ち時間をゼロにするMATLABプログラミング術: 遅いコードを劇的に変える最適化の技術 ― ベクトル化からGPU・MEX活用まで高速化実践入門
著者:美山 ゆい(著) 個人出版 2026/9/10(木)配信
5leaf.jp
September 11, 2026 at 9:51 PM
5 threat actors identified. 2 actively exploited 0-days. 2 supply chain ops. 1 KEV listing.

Patch FortiClient EMS. Verify TrueConf integrity. Audit npm dependencies. Rotate secrets.

#CyberSecurity #InfoSec
September 10, 2026 at 9:01 PM
📋 CISA adds TrueConf CVE-2026-3502 to KEV catalog. Download without integrity check → arbitrary code execution via tampered updates. Remediation deadline: April 16.

cybersecuritynews.com
September 10, 2026 at 9:00 PM
📋 CISA adds TrueConf CVE-2026-3502 to KEV catalog. Download without integrity check → arbitrary code execution via tampered updates. Remediation deadline: April 16.

cybersecuritynews.com
September 8, 2026 at 9:00 PM
5 threat actors identified. 2 actively exploited 0-days. 2 supply chain ops. 1 KEV listing.

Patch FortiClient EMS. Verify TrueConf integrity. Audit npm dependencies. Rotate secrets.

#CyberSecurity #InfoSec
August 28, 2026 at 9:01 PM
📋 CISA adds TrueConf CVE-2026-3502 to KEV catalog. Download without integrity check → arbitrary code execution via tampered updates. Remediation deadline: April 16.

cybersecuritynews.com
August 28, 2026 at 9:01 PM
📰 Homeland security cybercops advise patching TrueConf if using it due to Ukrainian hacktivists exploiting bugs, though TrueConf's rea...

🔗 https://www.theregister.com/patches/2026/08/21/homeland-security-cybercops-say-patch-trueconf-russias-zoom-if-youre-using-it/5291156

#Tech #Enterprise
Homeland security cybercops say patch TrueConf (Russia
Ukrainian hacktivists exploiting the bugs, but TrueConf
www.theregister.com
August 28, 2026 at 2:38 PM
Entra ID CVSS 10 — no patch to apply.
AI scripts → Siemens PLC memory/ladder logic.
GitLab → unauthenticated, exploited in minutes.
TrueConf → Head Mare, PhantomCore malware.
ShieldBreak → Defender patch bypassed. No fix.

🇬🇧 diesec.com/2026/08/top-...

#Cybersecurity #DIESEC
August 28, 2026 at 8:15 AM
Head Mare Hackers Exploit TrueConf Servers to Spread Backdoors Through Malicious Updates #Backdoors #CyberSecurity #ExposedServers
Head Mare Hackers Exploit TrueConf Servers to Spread Backdoors Through Malicious Updates
 The Head Mare hacktivist group has been targeting unpatched True Conf video conferencing enterprise servers to replace legitimate client installers with malware-containing versions, Kaspersky said. TrueConf is a business communication tool popular in Russia among enterprises and government agencies as an on-premise alternative to western video conferencing products like Zoom and Microsoft Teams.  Kaspersky researchers discovered the attacks in July and identified that Head Mare hackers used TCP port 4307, which is open by default, to connect to the target TrueConf servers without authentication, and exploit the vulnerabilities KLCERT-26-057 and KLCERT-26-058, which have been tracked by KLCERT. They allowed the attackers to run a malicious script in an isolated TrueConf environment, bypass the sandbox and execute commands on the underlying operating system.  The attackers then elevated their privileges to NT AUTHORITY\SYSTEM and replaced the \public\js\locale.php file with a web shell, which provided persistent remote access to the compromised server. Kaspersky said that Head Mare uses the web shell to collect sensitive information and access the TrueConf database and replace the legitimate TrueConf Client installer on the server with a malicious version containing the PhantomCore backdoor.  When members of an organization connect to a compromised local TrueConf server, they can receive the trojanized installer as an update. Kaspersky also warned that employees could be exposed even if their own organization does not use TrueConf. Employees connecting to compromised TrueConf servers operated by counterparties to participate in online meetings can download infected installation packages. Head Mare also deploys PhantomGraph, another backdoor consisting of two dll files: SysExcSvc.dll and SysReadSvc.dll.  The malware is capable of receiving commands through a Microsoft OneDrive account, executing these commands and returning the results. Observed activity comprised extracting the memory of the Local Security Authority Subsystem Service (LSASS) process to extract credentials, conducting reconnaissance by executing commands such as hostname and whoami, and establishing a reverse SSH tunnel. Kaspersky said that it is observing multiple active Head Mare campaigns targeting Russian organizations in instrumentation, electronics, transportation, energy, IT and software development.  The group has used phishing, exploitation of public facing web servers and access through contractors as initial access methods. The exploited TrueConf vulnerabilities affected versions 5.3.x before 5.3.9, 5.4.x before 5.4.9 and 5.5.x before 5.5.5, as well as older versions. TrueConf fixed the vulnerabilities in versions 5.3.9, 5.4.9 and 5.5.5, which were released on June 18.  The attacks followed another campaign reported by Check Point Research in April 2026, in which hackers exploited a zero-day arbitrary file execution vulnerability in TrueConf, tracked as CVE-2026-3502, to compromise users through trojanized client updates.
dlvr.it
August 27, 2026 at 5:59 PM
5 threat actors identified. 2 actively exploited 0-days. 2 supply chain ops. 1 KEV listing.

Patch FortiClient EMS. Verify TrueConf integrity. Audit npm dependencies. Rotate secrets.

#CyberSecurity #InfoSec
August 26, 2026 at 9:02 PM
📋 CISA adds TrueConf CVE-2026-3502 to KEV catalog. Download without integrity check → arbitrary code execution via tampered updates. Remediation deadline: April 16.

cybersecuritynews.com
August 26, 2026 at 9:01 PM
Unauthenticated RCE hits WebLogic Zimbra TrueConf as Lazarus. AI powered UAT 10147 escalate. 274 Zimbra servers already owned. Patch hunt or lose the perimeter. Read Inferlume here: inferlume.com/reports/dail...

#ThreatIntel #CyberSecurity #SOC #CISA #VulnerabilityManagement #DetectionEngineering
Oracle Zimbra TrueConf Flaws Ignite Perimeter Meltdown with Lazarus AI Actors - Inferlume
{{rh9e7yNRO}}
inferlume.com
August 25, 2026 at 5:59 PM
CISA orders feds to patch actively exploited TrueConf Server flaws — another sign that critical comms infrastructure is under active…

https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-trueconf-server-flaws/

#cybersecurity #infosec
August 25, 2026 at 1:30 PM
CISAが連邦民間機関に対し、悪用されているTrueConf Serverの脆弱性へのパッチ適用を命令

eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More...
CISAが連邦民間機関に対し、悪用されているTrueConf Serverの脆弱性へのパッチ適用を命令
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More
blackhatnews.tokyo
August 24, 2026 at 7:09 PM
CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities www.securityweek.com/cisa-urges-i...
CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities
The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware.
www.securityweek.com
August 24, 2026 at 12:12 PM
Top vendors in this batch: Microsoft (3), TrueConf (2), Cisco (2).
August 24, 2026 at 11:38 AM
Same story different day, with CISA gifting us nine actively exploited vulnerabilities across enterprise infrastructure. Anyone running VMware vCenter Syslog components is blessed with unauthenticated remote code execution, alongside lucky administrators managing TrueConf and Zim...

Read full story
August 24, 2026 at 6:40 AM
🟠 Vulnérabilités : CISA impose le patch de 2 failles TrueConf Server exploitées ; Microsoft corrige une faille Entra ID max exploitée ; CERT-FR : Apple, Cisco, Splunk, GitLab, Windows.
https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-trueconf-server-flaws/
August 24, 2026 at 6:34 AM