U.S. CISA adds a flaw in TrueConf Client to its Known Exploited Vulnerabilities catalog
ID: f1217cf3-bced-5a81-ab96-04449b72d484
STIX ID: report--f1217cf3-bced-5a81-ab96-04449b72d484
Feed Name: Security Affairs
Threat Score
CISA added CVE-2026-3502 — a TrueConf Client flaw that allows unverified updates to be installed — to its Known Exploited Vulnerabilities catalog after reports that attackers compromised on‑premises TrueConf update servers to push malicious updates (delivering the Havoc framework) to government video‑conferencing deployments; Check Point calls the activity Operation TrueChaos, links it to a China‑aligned actor, and CISA ordered federal remediation by April 16, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
