Story thread · 2 reports / 2 sources

TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore

thehackernews.com · 1d

TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore

The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors. Russian cybersecurity vendor Kaspersky said it detected the attacks in July 2026. The activity involves exploiting a vulnerability chain

First report: Hackers breach TrueConf to trojanize client installers with backdoors bleepingcomputer.com, 3d

The conversation · 0

Sign in to join the conversation.

No comments yet — start the thread.