Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Bitcoin Has Its Best Week Since 2023 As Shortsellers Continue To Get Wiped Out

    August 22, 2026

    Hidden magnetism inside atoms may explain mysterious gamma rays

    August 22, 2026

    Secret Plan to Dump Slaughterhouse Waste Blindsided Residents of Iowa’s Loess Hills

    August 22, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Bitcoin Has Its Best Week Since 2023 As Shortsellers Continue To Get Wiped Out
    • Hidden magnetism inside atoms may explain mysterious gamma rays
    • Secret Plan to Dump Slaughterhouse Waste Blindsided Residents of Iowa’s Loess Hills
    • Sherman Phoenix remains a symbol of growth for Milwaukee business owners
    • Young Africans Love Donald Trump. Why?
    • Middle East live: Iran allows several Iraqi oil tankers to pass through Hormuz strait
    • How a Progressive Democrat in Florida Gave Her Party New Hope — and New Fears
    • Michael Polansky is training an AI model on skin that’s still alive
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 22
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 22, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The US cybersecurity agency CISA on Thursday warned federal agencies that threat actors have been exploiting two vulnerabilities in TrueConf.

    A secure on-premises video conferencing platform, TrueConf relies on Scalable Video Coding (SVC) to connect client applications through a dedicated corporate server.

    All TrueConf Server versions since 2022 contain two critical-severity bugs tracked as CVE-2026-72529 and CVE-2026-72530 that allow attackers to execute arbitrary code.

    The two vulnerabilities can be exploited by remote attackers with access to the TrueConf server via port 4307/TCP. CVE-2026-72529 allows the attacker to call an undocumented function and execute arbitrary scripts, while CVE-2026-72530 enables them to escape the isolated environment and execute scripts on the host system.

    The exploited vulnerabilities were addressed in June 2026, in TrueConf Server versions 5.3.9, 5.4.9 and 5.5.5.

    On Thursday, CISA added both to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch the former within three days and the latter within two weeks.

    Advertisement. Scroll to continue reading.

    While CISA has not shared details on the observed exploitation, earlier this month Kaspersky warned that they have been exploited by the hacktivist group Head Mare to deploy the PhantomCore malware.

    Active since at least 2023, Head Mare has been targeting organizations in Russia and Belarus in destructive attacks. It has been observed deploying file-encrypting malware and demanding ransom payments from its victims, but the group does not appear to be financially motivated.

    As part of the attacks investigated by Kaspersky, the hackers exploited CVE-2026-72529 and CVE-2026-72530 to compromise an organization’s TrueConf server and replace one of its files with a web shell.

    “This web shell is later used to gather information about the IT infrastructure of the attacked organization, gain privileged access to the TrueConf Server database, and replace the legitimate client installers,” Kaspersky says.

    The threat actors placed malicious TrueConf client installers on the server. Once executed on the employee’s systems, they installed PhantomCore, a piece of malware typically associated with Head Mare’s intrusions.

    Additionally, the attackers installed a backdoor on the *nix servers running TrueConf, and another on *nix systems. The former uses the TrueConf protocol for command-and-control (C&C) communication, while the latter uses GitHub.

    TrueConf server owners are advised to update to a patched version, scan their environments for indicators of compromise (IoCs), scan for malicious artifacts, and rotate the credentials for all potentially affected accounts if an intrusion is detected.

    Related: Hackers Target Zimbra Servers in Active Exploitation Campaign

    Related: Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities

    Related: MLflow Vulnerability Exploited for Cloud Credential Theft

    Related: Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities

    CISA Exploited Patching TrueConf urges Vulnerabilities
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

    Wazuh and AI For Enhanced SOC Workflows

    Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind

    New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

    Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

    Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Bitcoin Has Its Best Week Since 2023 As Shortsellers Continue To Get Wiped Out

    August 22, 2026

    Hidden magnetism inside atoms may explain mysterious gamma rays

    August 22, 2026

    Secret Plan to Dump Slaughterhouse Waste Blindsided Residents of Iowa’s Loess Hills

    August 22, 2026

    Sherman Phoenix remains a symbol of growth for Milwaukee business owners

    August 22, 2026
    Latest Posts

    ‘Running Away Balloon’ Artist Sues AI Meme Generator Over Ad Templates

    July 28, 2026

    Hush Security Raises $30 Million for AI Agent Governance

    July 28, 2026

    Armenia’s AI Bet Is Not Chip Manufacturing. It Is Compute Sovereignty 

    July 28, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Bitcoin Has Its Best Week Since 2023 As Shortsellers Continue To Get Wiped Out

    August 22, 2026

    Hidden magnetism inside atoms may explain mysterious gamma rays

    August 22, 2026

    Secret Plan to Dump Slaughterhouse Waste Blindsided Residents of Iowa’s Loess Hills

    August 22, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.