Hackers exploit TrueConf zero-day to push malicious software updates
ID: fd2c9153-d673-51ae-98fe-bcfa10b8cc17
STIX ID: report--fd2c9153-d673-51ae-98fe-bcfa10b8cc17
Feed Name: Bleeping Computer
Check Point disclosed active exploitation of a TrueConf zero-day (CVE-2026-3502) that abuses a missing integrity check in the update mechanism to distribute malicious updates and execute arbitrary files on connected endpoints; the "TrueChaos" campaign is attributed with moderate confidence to a Chinese-nexus actor targeting government entities in Southeast Asia, leveraging DLL sideloading, UAC bypass, and likely the Havoc C2 framework, affecting TrueConf versions 8.1.0–8.5.2 and patched in 8.5.3.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
