Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it
Ukrainian hacktivists exploiting the bugs, but TrueConf's reach stretches well beyond home turf
The US federal government has instructed agencies to apply security patches for two recently discovered vulnerabilities in TrueConf, a video conferencing platform developed in Russia. The Computer Emergency Readiness Team (CISA) added these flaws to its Known Exploited Vulnerabilities catalog, indicating they have already been exploited in real-world attacks.
The flaws, identified as CVE-2026-72529 and CVE-2026-72530, can give attackers control over the underlying server. Kaspersky, a security firm, linked the attacks to Head Mare, a pro-Ukrainian hacktivist group known for targeting Russian organizations. Head Mare used the vulnerabilities to plant a web shell, move laterally within victims' infrastructure, and gain privileged access to the TrueConf database.
The attackers then replaced the legitimate TrueConf client with a trojanized version containing the PhantomCore backdoor. While TrueConf has users worldwide, including in Switzerland and Istanbul, most of its customers are Russian. The vulnerabilities affect TrueConf Server versions dating back to 2022, and fixes were released in versions 5.3.9, 5.4.9, and 5.5.5 on June 18. Federal agencies have until September 10 to patch the flaws.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.