[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fMcDvO-u9pfLyJrzR4xo_K0jGAqtQqBANsIVnVE52O1g":3},{"article":4,"iocs":52},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":29,"category":30,"article_tags":34},"f78ce2f7-428f-40ff-a575-f11cd946dc8b","CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities","cisa-urges-immediate-patching-of-exploited-trueconf-vulnerabilities-be976a","The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware. The post CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities appeared first on SecurityWeek.","CISA has issued a warning about two critical vulnerabilities in TrueConf Server that are being actively exploited by the Head Mare hacktivist group to deploy the PhantomCore malware. These bugs allow for arbitrary code execution and host system compromise. TrueConf has released patches for these vulnerabilities, and CISA is urging federal agencies to apply them immediately.","CISA warns of exploited TrueConf vulnerabilities leading to PhantomCore malware deployment.","The US cybersecurity agency CISA on Thursday warned federal agencies that threat actors have been exploiting two vulnerabilities in TrueConf. A secure on-premises video conferencing platform, TrueConf relies on Scalable Video Coding (SVC) to connect client applications through a dedicated corporate server. All TrueConf Server versions since 2022 contain two critical-severity bugs tracked as CVE-2026-72529 and CVE-2026-72530 that allow attackers to execute arbitrary code. The two vulnerabilities can be exploited by remote attackers with access to the TrueConf server via port 4307\u002FTCP. CVE-2026-72529 allows the attacker to call an undocumented function and execute arbitrary scripts, while CVE-2026-72530 enables them to escape the isolated environment and execute scripts on the host system. The exploited vulnerabilities were addressed in June 2026, in TrueConf Server versions 5.3.9, 5.4.9 and 5.5.5. On Thursday, CISA added both to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch the former within three days and the latter within two weeks.Advertisement. Scroll to continue reading. While CISA has not shared details on the observed exploitation, earlier this month Kaspersky warned that they have been exploited by the hacktivist group Head Mare to deploy the PhantomCore malware. Active since at least 2023, Head Mare has been targeting organizations in Russia and Belarus in destructive attacks. It has been observed deploying file-encrypting malware and demanding ransom payments from its victims, but the group does not appear to be financially motivated. As part of the attacks investigated by Kaspersky, the hackers exploited CVE-2026-72529 and CVE-2026-72530 to compromise an organization’s TrueConf server and replace one of its files with a web shell. “This web shell is later used to gather information about the IT infrastructure of the attacked organization, gain privileged access to the TrueConf Server database, and replace the legitimate client installers,” Kaspersky says. The threat actors placed malicious TrueConf client installers on the server. Once executed on the employee’s systems, they installed PhantomCore, a piece of malware typically associated with Head Mare’s intrusions. Additionally, the attackers installed a backdoor on the *nix servers running TrueConf, and another on *nix systems. The former uses the TrueConf protocol for command-and-control (C&C) communication, while the latter uses GitHub. TrueConf server owners are advised to update to a patched version, scan their environments for indicators of compromise (IoCs), scan for malicious artifacts, and rotate the credentials for all potentially affected accounts if an intrusion is detected. Related: Hackers Target Zimbra Servers in Active Exploitation Campaign Related: Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities Related: MLflow Vulnerability Exploited for Cloud Credential Theft Related: Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScalerCritical GitLab Flaw Exploited Shortly After DisclosurePrevalent AI Raises $22 Million to Expand Data Fabric PlatformUS Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of ThemCISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities943 Patches Rolled Out With Oracle’s August 2026 Security UpdateChrome, Firefox Updates Patch Dozens of VulnerabilitiesXpander Raises $7.5 Million for AI Management and Governance Latest News Hackers Target Zimbra Servers in Active Exploitation CampaignSurveillance – Everything You Wanted to Know, But Were Afraid to AskThreat Actor Hacks 14,000 IP Cameras in Ukraine and RussiaAtlassian, Splunk Patch Dozens of Critical, High-Severity VulnerabilitiesMLflow Vulnerability Exploited for Cloud Credential TheftCisco Patches Critical Crosswork, Secure Workload VulnerabilitiesAI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian HackingOpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveDaniel Dubowski has been named Senior Vice President and Chief Information Security Officer at Marriott International.Allied Universal has named Jordan Avnaim Global Chief Information Security Officer.Cycode has promoted Seth Robbins to President and Chief Revenue Officer.More People On The MoveExpert Insights The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fcisa-urges-immediate-patching-of-exploited-trueconf-vulnerabilities\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2025\u002F07\u002FCISA-KEV.jpg","2026-08-21T07:25:50+00:00","2026-08-21T08:00:26.661275+00:00",9,[18,21,24,27],{"name":19,"type":20},"TrueConf Server","product",{"name":22,"type":23},"Head Mare","threat_actor",{"name":25,"type":26},"TrueConf","vendor",{"name":28,"type":20},"Scalable Video Coding (SVC)","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":29,"icon":31,"name":32,"slug":33},null,"Vulnerabilities","vulnerabilities",[35,40,42,47],{"category":36},{"id":37,"icon":31,"name":38,"slug":39},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":41},{"id":29,"icon":31,"name":32,"slug":33},{"category":43},{"id":44,"icon":31,"name":45,"slug":46},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":48},{"id":49,"icon":31,"name":50,"slug":51},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[53,57,60,63,66],{"type":54,"value":55,"context":56},"cve","CVE-2026-72529","Vulnerability allowing arbitrary script execution in TrueConf.",{"type":54,"value":58,"context":59},"CVE-2026-72530","Vulnerability allowing script execution on host system in TrueConf.",{"type":46,"value":61,"context":62},"PhantomCore","Malware deployed by Head Mare group after exploiting TrueConf vulnerabilities.",{"type":46,"value":64,"context":65},"web shell","Used by attackers to gather information and gain access after compromising TrueConf server.",{"type":46,"value":67,"context":68},"backdoor","Installed on *nix servers for C&C communication or via GitHub."]