CVE-2026-72530 — TrueConf Server Code Injection Vulnerability
TrueConf Server Code Injection Vulnerability Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based…
TrueConf Server Code Injection Vulnerability Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based…
TrueConf Server Missing Authentication for Critical Function Vulnerability Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing…
Russian cybersecurity vendor Kaspersky has uncovered a new attack campaign by the threat actor known as Head Mare, targeting unpatched TrueConf videoconferencing…
CVE-2026-3502 is a high-severity security flaw in the TrueConf client that was exploited as a zero-day in campaigns targeting government entities in…
Head Mare is a threat actor that has been observed exploiting vulnerabilities in TrueConf servers to deliver backdoors and remote access trojans.…
PhantomCore is a backdoor and remote access trojan (RAT) delivered through poisoned TrueConf client installers. It is part of an attack chain…
Positive Technologies is a cybersecurity company that disclosed three vulnerabilities in TrueConf software (BDU:2025-10114, BDU:2025-10115, BDU-2025-10116) that were exploited by Head Mare.…
TrueConf is a videoconferencing software vendor whose server and client products have been targeted by threat actors. They have released patches for…
Havoc C2 is a command-and-control framework that was deployed in campaigns exploiting CVE-2026-3502, a zero-day in the TrueConf client. The attacks targeted…