Homeland security cybercops say patch TrueConf (Russia’s Zoom) if you’re using it

← Back to the feed

Homeland security cybercops say patch TrueConf (Russia’s Zoom) if you’re using it

The Register · 3 hours ago

The US Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch two actively exploited vulnerabilities in TrueConf, a Moscow-based video conferencing platform often described as a Russian alternative to Zoom. The move follows reports that compromised TrueConf servers were being used to distribute malware to meeting participants, raising concerns given the software's use by organisations well beyond Russia, including a Swiss government department and Istanbul Airport.

CISA added CVE-2026-72529 and CVE-2026-72530 to its Known Exploited Vulnerabilities catalogue, though it has not disclosed who has been targeted. The only documented attacks, reported by Kaspersky, were carried out by the pro-Ukrainian hacktivist group Head Mare against Russian firms in sectors such as transport and energy; combined, the flaws let an unauthenticated attacker with access to TrueConf's default port take full control of a server, which Head Mare used to plant a web shell and distribute a trojanised installer carrying the PhantomCore backdoor. The bugs affect TrueConf Server versions dating back to 2022, with fixes issued on 18 June in versions 5.3.9, 5.4.9 and 5.5.5; exploitation requires network access to the vulnerable service, so internet-facing or supplier-hosted servers pose the greatest risk.

  • CISA orders US agencies to patch two exploited TrueConf flaws
  • Pro-Ukrainian hackers Head Mare used bugs to plant backdoor
  • Fixes shipped in June; unpatched internet-facing servers most at risk

Cybersecurity Europe Technology World

Read the full article at the source →