logo

CISA gives agencies two weeks to patch video conferencing bug exploited by Chinese hackers

ID: 26ae8bdb-f88b-5076-978f-5c107f29e9e5

STIX ID: report--26ae8bdb-f88b-5076-978f-5c107f29e9e5

Feed Name: The Record from Recorded Future News

Threat Score
75/100

Date Published: 2026-04-03

Date Updated: 2026-05-01

...
...

CISA and Check Point warn that CVE-2026-3502—a 7.8-severity flaw in TrueConf’s updater validation—has been actively exploited to push weaponized updates from compromised on-premises TrueConf servers to government endpoints in Southeast Asia; Check Point attributes the TrueChaos campaign to Chinese actors leveraging Havoc and ShadowPad, and CISA ordered federal agencies to patch within two weeks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.