Hackers used flaws in TrueConf video-conferencing servers to break in and replace legitimate client installers with malware-laced versions, putting organizations and even outside meeting participants at risk. Kaspersky says Head Mare exploited two TrueConf Server bugs it tracks as KLCERT-26-057 and KLCERT-26-058 on TCP port 4307 to get unauthenticated code execution, escape the product's sandbox, gain NT AUTHORITY\SYSTEM, install a web shell, and deploy PhantomCore and PhantomGraph. Affected versions are 5.3.x before 5.3.9, 5.4.x before 5.4.9, and 5.5.x before 5.5.5; fixes were released June 18.
Why it matters: Organizations running on-premises TrueConf servers should patch immediately and treat unpatched servers as potentially compromised, because attackers can turn normal software updates into malware delivery. This also affects users who connect to a partner's compromised TrueConf server, so admins should verify installer signatures and hunt for web shells, LSASS credential dumping, and PhantomCore or PhantomGraph artifacts.
2026.08.21
95% relevant
This is the same underlying exploitation campaign and vulnerability pair, adding that CISA has now placed CVE-2026-72529 and CVE-2026-72530 in the KEV catalog and ordered U.S. federal agencies to patch by September 10, confirming active exploitation beyond just the earlier vendor and researcher reporting.
Sergiu Gatlan
2026.08.21
95% relevant
This article directly updates that same underlying event by adding that CISA has now placed the two exploited TrueConf Server flaws, CVE-2026-72529 and CVE-2026-72530, in the KEV catalog and ordered federal agencies to patch by September 3, confirming active exploitation beyond the earlier Kaspersky reporting.
Ionut Arghire
2026.08.21
96% relevant
This article updates the same underlying exploitation campaign by adding that CISA has now formally added CVE-2026-72529 and CVE-2026-72530 in TrueConf Server to the KEV catalog, set federal remediation deadlines, and reiterated patch versions 5.3.9, 5.4.9, and 5.5.5.
info@thehackernews.com (The Hacker News)
2026.08.10
99% relevant
This is the same underlying event: Head Mare exploited TrueConf Server flaws to replace legitimate client installers with PhantomCore malware, updating or corroborating the existing report about backdoored TrueConf client distributions.
Bill Toulas
2026.08.08
100% relevant
This article establishes a distinct ongoing intrusion campaign against TrueConf servers in which exploited server flaws are used to trojanize downstream client installers with PhantomCore and PhantomGraph.
← Back to all stories