TrueConf zero-day vulnerability exploited to target government networks
ID: 5f6aff47-694c-588d-8d65-417b8cefdd99
STIX ID: report--5f6aff47-694c-588d-8d65-417b8cefdd99
Feed Name: Help Net Security
Threat Score
Check Point researchers observed a zero-day (CVE-2026-3502) in the TrueConf videoconferencing client being abused to push weaponized on‑premises updates to government networks in Southeast Asia, delivering the Havoc post‑exploitation framework; the campaign (Operation TrueChaos) is attributed with moderate confidence to a China‑nexus actor and the issue is patched in TrueConf Windows client v8.5.3 (March 2026).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
