Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it
Ukrainian hacktivists exploiting the bugs, but TrueConf's reach stretches well beyond home turf
CISA has ordered US federal agencies to patch two exploited flaws in TrueConf, a Russian-built video conferencing platform, after compromised servers were caught handing malware to unsuspecting meeting participants.
The US cybersecurity agency on Thursday added CVE-2026-72529 and CVE-2026-72530to its Known Exploited Vulnerabilities catalog, saying both have been used in real-world attacks. What CISA doesn't say is who is being attacked, or where.
The only publicly documented attacks exploiting these two bugs so far come from Kaspersky, which linked them to Head Mare, a pro-Ukrainian hacktivist group that has repeatedly gone after Russian organizations. Its latest campaign targeted Russian companies across industries including transport, energy, electronics, IT, and software development.
CISA doesn't say whether it added the flaws to KEV because of those attacks or because it has evidence of exploitation elsewhere, potentially including against...
Copyright of this story solely belongs to theregister.com. To see the full text click HERE