Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it
Ukrainian hacktivists exploiting the bugs, but TrueConf's reach stretches well beyond home turf
CISA (Cybersecurity and Infrastructure Security Agency) has ordered US federal agencies to patch two exploited vulnerabilities in TrueConf, a video conferencing platform developed in Russia. These flaws, CVE-2026-72529 and CVE-2026-72530, have been employed in real-world attacks, according to the agency. Head Mare, a pro-Ukrainian hacktivist group, has been linked to attacks exploiting these vulnerabilities. The agency has not clarified the extent and location of the attacks.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.