Operation TrueChaos: Exploitation of TrueConf Zero-Day Vulnerability
ID: 799b93b3-778c-5803-b691-351a891b00e0
STIX ID: report--799b93b3-778c-5803-b691-351a891b00e0
Feed Name: ThreatCluster
Threat Score
Operation TrueChaos exploited a zero-day in TrueConf (CVE-2026-3502) that bypassed update integrity checks, allowing attackers to execute arbitrary files by replacing legitimate updates. The campaign targeted government entities in Southeast Asia via compromised on-premises TrueConf servers, was attributed to a Chinese-nexus threat actor, and a patch was released in March 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
