Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it
ID: 2af78e4a-98c3-57de-a78e-c123239d7ab6
STIX ID: report--2af78e4a-98c3-57de-a78e-c123239d7ab6
Feed Name: The Register (Security)
Threat Score
## Executive summary CISA added two TrueConf Server vulnerabilities (CVE-2026-72529 and CVE-2026-72530) to its Known Exploited Vulnerabilities list after Kaspersky reported Head Mare exploitations that allowed unauthenticated RCE on servers, web shell deployment, lateral movement, and trojanizing the TrueConf Windows client with the PhantomCore backdoor; fixes were released in TrueConf 5.3.9 / 5.4.9 / 5.5.5 and US federal agencies must patch by September 10.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
