Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it
CISA has ordered US federal agencies to patch two exploited flaws in TrueConf, a Russian-built video conferencing platform, after compromised servers were caught handing malware to unsuspecting meeting participants.
The US cybersecurity agency on Thursday added CVE-2026-72529 and CVE-2026-72530 to its Known Exploited Vulnerabilities catalog, saying both have been used in real-world attacks.
What CISA doesn't say is who is being attacked, or where.
The only publicly documented attacks exploiting these two bugs so far come from Kaspersky, which linked them to Head Mare, a pro-Ukrainian hacktivist group that has repeatedly gone after Russian organizations.
Its latest campaign targeted Russian companies across industries including transport, energy, electronics, IT, and software development.
CISA doesn't say whether it added the flaws to KEV because of those attacks or because it has evidence of exploitation elsewhere, potentially including against organizations in the US.
That question is particularly interesting given what TrueConf is and who uses it.
TrueConf is a Moscow-based maker of video conferencing software that offers an on-premises alternative to cloud services such as Zoom and Microsoft Teams.
Organizations can run TrueConf Server on their own infrastructure, including in private networks, giving them control over where their calls and associated data go.
While the company's roots and much of its customer base are Russian, TrueConf has users worldwide.
It says it has users in its portfolio that include Switzerland’s Department of Justice and Home Affairs, Istanbul Airport, and a news org, which The Reg has contacted to confirm.
Most of the customer success stories are dated before 2022.
Used together, the two bugs flagged by CISA can give an attacker control of the underlying server.
According to Kaspersky, an unauthenticated attacker with network access to TCP port 4307, which TrueConf documentation says is open by default, can exploit the first flaw to run a malicious script.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.