logo

TrueConf zero-day vulnerability exploited to target government networks

ID: 5f6aff47-694c-588d-8d65-417b8cefdd99

STIX ID: report--5f6aff47-694c-588d-8d65-417b8cefdd99

Feed Name: Help Net Security

Threat Score
88/100

Date Published: 2026-04-02

Date Updated: 2026-04-28

Author: Sinisa Markovic

...
...

Check Point researchers observed a zero-day (CVE-2026-3502) in the TrueConf videoconferencing client being abused to push weaponized on‑premises updates to government networks in Southeast Asia, delivering the Havoc post‑exploitation framework; the campaign (Operation TrueChaos) is attributed with moderate confidence to a China‑nexus actor and the issue is patched in TrueConf Windows client v8.5.3 (March 2026).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.