Skip to main content

Tag: trueconf

3 articles

Video conferencing device on a conference room table surrounded by empty chairs.

CISA Warns of Exploited Flaws in Russian Video Conferencing Platform TrueConf

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about two critical vulnerabilities in TrueConf, a Russian video conferencing platform, that have already been exploited in real-world attacks. Federal agencies have just until September 10 to patch these flaws and protect themselves.

Analyst 207
Head Mare APT Exploits Unpatched TrueConf Servers to Deliver PhantomCore Malware

Head Mare APT Exploits Unpatched TrueConf Servers to Deliver PhantomCore Malware

In a sneaky move, the Head Mare group exploited unpatched TrueConf servers to spread PhantomCore malware, using a chain of vulnerabilities to swap out legitimate client installers with infected ones. This allowed them to secretly deliver a backdoor to unsuspecting meeting participants.

Analyst 207
Rows of computer servers and equipment in a brightly-lit server room.

Hackers Breach TrueConf Servers to Deploy Backdoors via Trojanized Updates

Hackers have breached TrueConf servers by exploiting a gaping security hole - an open TCP port that lets them in without needing a password, then using trojanized updates to deploy backdoors and take control. This sneaky attack vector has been used by threat actors like Head Mare to spread malware and gain unauthorized access.

Analyst 207