Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it

Aug 21, 2026 - 23:11
0 0
Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it

PATCHES

Ukrainian hacktivists exploiting the bugs, but TrueConf's reach stretches well beyond home turf 

CISA has ordered US federal agencies to patch two exploited flaws in TrueConf, a Russian-built video conferencing platform, after compromised servers were caught handing malware to unsuspecting meeting participants.

The US cybersecurity agency on Thursday added CVE-2026-72529 and CVE-2026-72530 to its Known Exploited Vulnerabilities catalog, saying both have been used in real-world attacks. What CISA doesn't say is who is being attacked, or where.

The only publicly documented attacks exploiting these two bugs so far come from Kaspersky, which linked them to Head Mare, a pro-Ukrainian hacktivist group that has repeatedly gone after Russian organizations. Its latest campaign targeted Russian companies across industries including transport, energy, electronics, IT, and software development.

CISA doesn't say whether it added the flaws to KEV because of those attacks or because it has evidence of exploitation elsewhere, potentially including against organizations in the US.

That question is particularly interesting given what TrueConf is and who uses it.

TrueConf is a Moscow-based maker of video conferencing software that offers an on-premises alternative to cloud services such as Zoom and Microsoft Teams. Organizations can run TrueConf Server on their own infrastructure, including in private networks, giving them control over where their calls and associated data go.

While the company's roots and much of its customer base are Russian, TrueConf has users worldwide. It says it has users in its portfolio that include Switzerland’s Department of Justice and Home Affairs, Istanbul Airport, and a news org, which The Reg has contacted to confirm. Most of the customer success stories are dated before 2022.

Used together, the two bugs flagged by CISA can give an attacker control of the underlying server. According to Kaspersky, an unauthenticated attacker with network access to TCP port 4307, which TrueConf documentation says is open by default, can exploit the first flaw to run a malicious script. The second flaw lets the attacker break out of the isolated environment where the script runs and execute arbitrary code on the underlying server.

Kaspersky says Head Mare used that access to plant a web shell, move through victims' infrastructure, and gain privileged access to the TrueConf database. From there, the attackers replaced the legitimate TrueConf Windows client installer on compromised servers with a trojanized version carrying the PhantomCore backdoor.

Kaspersky warns that this creates a risk beyond organizations actually running vulnerable TrueConf servers. Employees joining conferences hosted by suppliers or other third parties could potentially download a compromised client from someone else's hacked infrastructure.

The researcher says the flaws affect TrueConf Server releases going back to 2022. TrueConf shipped fixes in versions 5.3.9, 5.4.9 and 5.5.5 on June 18, warning customers that skipping the update could leave their conferencing systems exposed to attacks over the public internet.

That doesn't mean every TrueConf box is sitting on the internet waiting to be popped. Exploitation requires network access to the vulnerable service, so a server confined to an internal network would not be directly reachable from outside unless an attacker had another route in.

Federal agencies have until September 10 to patch the flaws. Other TrueConf admins can take their time, as long as they're comfortable with a conferencing server potentially moonlighting as a malware distribution point. ®

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0

Comments (0)

User