CVE-2026-72529Active Exploitation(trueconf / trueconf_server)

MEDIUMCVSS 9.3 · CRITICALCISA KEV

Exploitation observed; activity peaked at 18 mentions and remains active

Immediate actions

  • Patch trueconf trueconf_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.

5.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-08-23. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-306

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • trueconf_server

Threat summary

  • Active exploitation appears in 27 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 41 mentions across 11 observed days

What's happening

  • Active exploitation reported across 27 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 21 signals
  • Technical details provided in 28 signals
  • Disclosure: 8 classified signals
  • Peaked 8d ago at 18 mentions (2026-08-21); latest day: 1
  • 41 total mentions across 11 days

Affected systems

Vendors
Products
trueconf_server

Deep dive

Activity timeline41 mentions / 11d
0591418Mentions · 2026-08-19: 2Mentions · 2026-08-20: 5Mentions · 2026-08-21: 18Mentions · 2026-08-22: 4Mentions · 2026-08-23: 3Mentions · 2026-08-24: 4Mentions · 2026-08-28: 1Mentions · 2026-08-30: 1Mentions · 2026-08-31: 1Mentions · 2026-09-04: 1Mentions · 2026-09-30: 1PoC Mentioned / Linked · 2026-08-21: 1PoC Mentioned / Linked · 2026-09-04: 1Active Exploitation · 2026-08-20: 4Active Exploitation · 2026-08-21: 13Active Exploitation · 2026-08-22: 3Active Exploitation · 2026-08-23: 1Active Exploitation · 2026-08-24: 3Active Exploitation · 2026-08-30: 1Active Exploitation · 2026-08-31: 1Active Exploitation · 2026-09-04: 1Patch / Workaround · 2026-08-20: 4Patch / Workaround · 2026-08-21: 8Patch / Workaround · 2026-08-22: 2Patch / Workaround · 2026-08-23: 3Patch / Workaround · 2026-08-24: 2Patch / Workaround · 2026-08-30: 1Patch / Workaround · 2026-08-31: 1Technical Details · 2026-08-19: 2Technical Details · 2026-08-20: 2Technical Details · 2026-08-21: 13Technical Details · 2026-08-22: 2Technical Details · 2026-08-23: 3Technical Details · 2026-08-24: 3Technical Details · 2026-08-28: 1Technical Details · 2026-08-30: 1Technical Details · 2026-08-31: 108-1908-2008-2108-2208-2308-2408-2808-3008-3109-0409-30
Signal classification4 categories
Active Exploitation
2562.5%
Disclosure
820.0%
Patch
410.0%
General
37.5%
Referenced assets79 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-192
Disclosure2
2026-08-205
Active Exploitation4Disclosure1
2026-08-2118
Active Exploitation13Disclosure2General2Patch1
2026-08-224
Active Exploitation2General1Patch1
2026-08-233
Active Exploitation1Disclosure1Patch1
2026-08-244
Active Exploitation2Disclosure1Patch1
2026-08-281
Disclosure1
2026-08-301
Active Exploitation1
2026-08-311
Active Exploitation1
2026-09-041
Active Exploitation1
Full discourse20 posts
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-72529 (CVSS 9.8) + CVE-2026-72530 (CVSS 9.0): Unauthenticated RCE in TrueConf Server 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJUcnVlQ29uZi1WQ1Mi 🎯2.9K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="TrueConf-VCS" 🔖Refer: https://www.scworld.com/news/trueconf-flaws-enabling-attacks-on-meeting-participants-added-to-kev-catalog #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The tweet announces the discovery of two high‑severity CVEs for TrueConf Server, providing technical details and referencing external security resources, but offers no PoC, exploit code, active exploitation evidence, or patch information.

    016038143.4K
    14.8K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️We added TrueConf Server vulnerabilities CVE-2026-72529 & CVE-2026-72530 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/dzrodjLszP

    Post summary

    The DHS alert adds TrueConf Server CVE‑2026‑72529 and CVE‑2026‑72530 to its catalog of known exploited vulnerabilities, urges organizations to apply mitigations, and signals that these weaknesses are being actively attacked.

    11113449.1K
    303.1K followersView on X
  • Cybernews@Cybernews
    Active Exploitation

    Actively exploited vulnerabilities CVE-2026-72529 and CVE-2026-72530 pose severe risks to federal systems. More details: https://cnews.link/trueconf-vulnerability-cisa-warning-3/ https://t.co/rWDqEhCMAW

    Post summary

    The post states that CVE-2026-72529 and CVE-2026-72530 are currently being exploited, posing severe risks to federal systems.

    1401231.4K
    72.7K followersView on X
  • Maxim Suhanov@errno_fail

    @anton_chuvakin One example – CVE-2026-72529 (unauth RCE): Exploitation discovered in June, fixed in June. Five urgent comms to update ASAP. * Two months later * CVE ID assigned in August. Listed in CISA KEV in August. 3-day patch deadline.

    11052501
    1.5K followersView on X
  • Machina Record@MachinaRecord
    Patch

    【リンク集:週末のセキュリティ関連ニュース/記事】 <脆弱性> ・シスコ、CrossworkとSecure Workloadに存在する脆弱性9件を修正 うち5件はCVSS 10.0(CVE-2026-20030、CVE-2026-20357他) https://thehackernews.com/2026/08/cisco-patches-nine-crosswork-and-secure.html ・MLFlowの重大な欠陥が悪用される 月間3,000万回ダウンロードされるAIプラットフォーム(CVE-2026-64849) https://hackread.com/attackers-exploit-critical-mlflow-ai-platform-flaw/ ・米CISA、悪用されているTrueConfサーバーの脆弱性へのパッチ適用を連邦政府機関に命じる(CVE-2026-72529、CVE-2026-72530) https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-trueconf-server-flaws/ ・ライブラリ「isolated-vm」の重大な脆弱性により、ホスト上でRCEが可能に https://www.securityweek.com/critical-isolated-vm-vulnerability-leads-to-rce-on-host/ ・マイクロソフト、最大深刻度の脆弱性を複数修正 コード実行や権限昇格を許す恐れ(CVE-2026-69836、CVE-2026-65816他) https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-max-severity-entra-id-flaw-exploited-in-attacks/ <マルウェア・その他脅威> ・Androidマルウェア「ToxicPanda」 VPN権限を悪用してGoogle Playをブロック https://www.bleepingcomputer.com/news/security/toxicpanda-android-malware-uses-vpn-permissions-to-block-google-play/ ・AndroidマルウェアがFirebaseを悪用し、ICICI・SBI・Axisなどインド各銀行になりすまし 政府の無効化通知で明らかに https://ministryofcyberaffairs.com/news/indian-banks-including-icici-sbi-axis-impersonated-by-android-malware-using-firebase-government-blocking-notices-show-48362865-20a2-4665-9df6-09386ad3e106 ・Microsoft Teams悪用のフィッシング攻撃で新マルウェア「SynkLoader」が拡散される https://www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/ ・車のヘッドユニット狙うマルウェアが発見される https://securelist.com/android-head-unit-malware/121106/ ・FTPバナーを悪用し、新種のWindows向けマルウェアが配布される https://www.bleepingcomputer.com/news/security/hackers-abuse-ftp-server-banners-to-deliver-new-windows-malware/ ・人気AIブランド装い、マルウェアを拡散する攻撃が複数確認される https://www.helpnetsecurity.com/2026/08/21/ai-brand-impersonation-malware-malware-research/ ・偽マネーロンダリング対策サイト、ユーザーを騙して暗号通貨の取引を承認させる https://hackread.com/fake-aml-sites-crypto-approving-malicious-transactions/ ・1万ドルで販売されるフィッシングキット、パスキー登録で乗っ取ったアカウントへの永続的なアクセスが可能と主張 https://www.theregister.com/cyber-crime/2026/08/21/10k-phishing-kit-claims-it-can-plant-rogue-passkeys-for-persistent-access-to-pwned-accounts/5291006 ・トロイの木馬化された14件のnpmパッケージ、AI活用するC2機能備えたLinux向けバックドアRedC2 4.0を配布 https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html ・バンキング型トロイの木馬Manic・Grandoreiro・ToxicPanda 2.0の詳細 https://www.securityweek.com/banking-trojans-manic-grandoreiro-toxicpanda-2-0-in-the-spotlight/ <データ侵害/サイバー犯罪> ・トロント小児病院のデータ侵害で職員と求職者の情報が流出 https://www.bleepingcomputer.com/news/security/sickkids-data-breach-exposes-employee-and-job-applicant-info/ ・米PE投資会社アポロがデータ侵害の発生を認める 金融大手狙ったハッキング攻撃が相次ぐさなか https://techcrunch.com/2026/08/21/private-equity-firm-apollo-confirms-data-breach-amid-hacking-wave-targeting-financial-giants/ <AI関連> ・暗号化されたプロンプトでGrokやGeminiの安全対策が破られる恐れ https://www.securityweek.com/encrypted-prompts-bypass-ai-safety-guardrails-in-grok-and-gemini/ ・自システムへの模擬攻撃にAIを活用しなければ、その隙を攻撃者に突かれることに https://www.theregister.com/security/2026/08/22/if-youre-not-using-ai-to-attack-your-own-systems-your-adversaries-will/5291346 ・暴走したAIモデルを制御する方法、最先端の研究所も依然明らかにせず https://techcrunch.com/2026/08/22/frontier-ai-labs-still-wont-say-how-theyd-contain-a-rogue-model/ ・OWASP、新セキュリティ指針でAIスキルの主要なリスクを指摘 https://www.darkreading.com/application-security/owasp-flags-top-ai-skill-risks-security-blueprint ・OpenAI、制御機能を複数追加 本来ならすでに実装されているべき? https://www.darkreading.com/application-security/openai-adds-controls-already ・AIのサイバー攻撃能力をベンチマークテストで順位付け https://www.aikido.dev/blog/ai-model-benchmarks-aug-21-2026 ・詳細不明のAIモデル「Ox Alpha」無料版、コーディングベンチマークでトップに https://startupfortune.com/a-mystery-model-called-ox-alpha-just-topped-coding-benchmarks-for-free/ ・AI企業が書籍を廃棄しているとして、複数の活動団体が米連邦取引委員会に苦情 https://www.theregister.com/ai-and-ml/2026/08/21/ai-companies-are-burning-books-advocates-complain-to-ftc/5291299 <サイバー戦/APT/国家型アクター/地政学関連> ・イラン系ハッカーの攻撃で英発電所が4日間停止 米水道施設への攻撃と同時期に発生 https://securityaffairs.com/197734/cyber-warfare-2/uk-power-plant-disabled-for-four-days-by-iran-linked-hackers-concurrent-with-us-water-attacks.html ・米政府の研究所が中国製LiDARにおけるセキュリティ上の欠陥を調査 https://techcrunch.com/2026/08/21/us-government-lab-is-probing-chinese-lidar-for-security-vulnerabilities/ <逮捕/テイクダウン/制裁/違反/その他法執行関連> ・Uberに8億2,500万ユーロの制裁金 ドライバーのアカウント自動停止をめぐるGDPR違反で https://techcrunch.com/2026/08/23/uber-faces-fine-of-nearly-1b-over-automated-driver-suspensions/ ・インド政府、銀行詐欺に関連するGoogle Firebaseアカウントの削除を命じる https://www.reuters.com/world/india/india-orders-removal-google-firebase-accounts-after-spotting-scam-pattern-2026-08-21/ <プライバシー> ・アリババ、ユーザー追跡目的でWebAudio使いフィンガープリンティングを作成 https://cyberinsider.com/alibaba-spotted-using-webaudio-fingerprinting-for-user-tracking/ ・TikTok、児童のプライバシー侵害訴訟で和解金4億米ドルの支払いに合意 https://techcrunch.com/2026/08/21/tiktok-reaches-400m-settlement-over-childrens-privacy-lawsuit/ ・米上院議員、法執行機関のハッキングツール使用法について見直すよう監査機関に要請 https://techcrunch.com/2026/08/21/senator-asks-us-federal-watchdog-to-review-how-feds-use-hacking-tools/ <リサーチ/攻撃手法/TTP> ・脅威インテリジェンス:Xユーザー狙ったDMCA関連の認証情報フィッシング https://ministryofcyberaffairs.com/news/threat-intelligence-dmca-themed-credential-phishing-targeting-x-twitter-users-cf7df827-ab3b-4ffc-a556-1c293a83d814 ・Windowsの名前付きパイプに危機 プロセス間通信を保全する方法 https://www.bleepingcomputer.com/news/security/named-pipes-under-attack-securing-windows-interprocess-communication/ ・漏洩状態のAWSキー数百件、悪用されれば企業アカウントの完全な乗っ取りが可能に https://www.bleepingcomputer.com/news/security/hundreds-of-leaked-aws-keys-give-full-control-over-corporate-accounts/ ・Microsoft Defenderの正規ドライバー、起動時にセキュリティソフトを削除する攻撃ツールとして悪用される可能性 https://thehackernews.com/2026/08/microsoft-defenders-own-driver-can-be.html <その他> ・「EchoBench」で自律型ペネトレーションテストツールを評価 人間による実測値を基準としたベンチマーク https://www.netspi.com/blog/technical-blog/ai-ml-pentesting/introducing-echobench-a-human-calibrated-benchmark-for-autonomous-pentesting/

    Post summary

    The article primarily reports vendor patch releases and evidence of active exploitation, with detailed technical information about the identified vulnerabilities.

    010223.7K
    1.3K followersView on X
  • YourDailyCVE@YourDailyCVE
    Active Exploitation

    🚨 CVE-of-the-Day: CVE-2026-72529 — TrueConf Server unauthenticated RCE via missing auth on port 4307, actively exploited CVSS: 9.8 | EPSS: 0.3% Unauthenticated attackers with network access to TCP/4307 can invoke an undocumented critical function and execute arbitrary scripts. Often chained with CVE-2026-72530 for full host takeover. #CVE #infosec

    Post summary

    The tweet announces CVE-2026-72529 as an unauthenticated RCE in TrueConf Server (port 4307, CVSS 9.8) claimed to be actively exploited, often chained with CVE-2026-72530, but provides no patch, workaround, or PoC reference.

    1002086
    34 followersView on X
  • CCB Alert@CCBalert
    Active Exploitation

    Warning: Critical Missing Authentication and Code Injection vulnerabilities in #TrueConfServer. CVE-2026-72529 CVSS: 9.3 / CVE-2026-72530 CVSS: 9.5. This actively exploited vulnerability chain results in remote code execution #RCE! Time to #Patch #Patch #Patch

    Post summary

    The post warns of two critical, actively exploited vulnerabilities in TrueConfServer (CVE-2026-72529 and CVE-2026-72530) that enable remote code execution and urges immediate patching.

    01001337
    7.2K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Active Exploitation

    CISA confirms two TrueConf Server flaws, CVE-2026-72529 and CVE-2026-72530, are exploited in the wild to deliver PhantomCore malware. Patch now. #TrueConf #CVE #ExploitedInTheWild #PhantomCore #HeadMare #InfoSec #PatchNow https://securityonline.info/trueconf-cve-2026-72529-exploited/

    Post summary

    CISA confirms that the two TrueConf Server CVEs are being actively exploited in the wild to deliver PhantomCore malware, and urges immediate patching.

    01001438
    12.9K followersView on X
  • Frontiera Tech@FrontieraTechIT
    Active Exploitation

    🛡️ CYBER BULLETIN | 2026/08/23 🚨 1. CISA flags actively exploited TrueConf Server flaws Two critical vulnerabilities in the self-hosted video platform (CVE-2026-72529 and CVE-2026-72530) landed in CISA’s KEV catalog. Attackers with network access can run arbitrary code; the Head Mare group has already used them to push malware. Federal agencies must patch ASAP. 2. Critical GitLab GraphQL bug under active exploitation CVE-2026-19478 (CVSS 9.4) lets unauthenticated attackers modify or delete public projects via a crafted GraphQL directive. Disclosed and patched mid-week, exploitation attempts hit honeypots within days. Self-managed instances need the latest updates now. 3. Microsoft Defender’s own driver can delete security software Check Point Research showed how the legitimate, signed BTR.sys boot-time remediation driver can be repurposed for kernel-level file and registry ops—enough to wipe AV/EDR components before they start. No real-world abuse seen yet, but the technique works across Windows 7 to 11 25H2. 4. Trojanized npm packages deliver AI-powered Linux backdoor Fourteen packages posing as harmless calendar/streak tools drop RedC2 4.0’s RedShell implant the moment they’re imported. The framework includes an LLM agent that turns natural-language commands into post-exploitation actions. Classic supply-chain risk for developers. #Cybersecurity #CISA #NIST

    Post summary

    Two critical CVEs (CVE‑2026‑72529/72530 and CVE‑2026‑19478) are actively exploited in the wild, with vendors urging immediate patching, while a new supply‑chain backdoor appears but has not yet been observed in real‑world abuse.

    1000098
    75 followersView on X
  • Techsico IT@Techsico_IT
    Patch

    IT/security teams running self-hosted TrueConf Server: patch now. CISA added CVE-2026-72529 and CVE-2026-72530 to KEV after active exploitation. Federal deadline: Sept. 3. Is TCP 4307 exposed? https://t.co/kJdtqYwCRA

    Post summary

    CISA has added CVE‑2026‑72529 and CVE‑2026‑72530 to its KEV list after active exploitation, urging IT/security teams to patch TrueConf Server before the September 3 federal deadline.

    0001030
    8 followersView on X
  • Frontiera Tech@FrontieraTechIT
    Active Exploitation

    🛡️ CYBER BULLETIN | 2026/08/22 🚨 1. CISA adds Zimbra OS command injection to KEV catalog CVE-2026-73570 is under active exploitation. Unauthenticated attackers can execute commands as the Zimbra user via crafted SMTP requests when SNMP notifications are enabled. Email server operators should verify patches and check logs for signs of compromise. 2. TrueConf Server flaws actively exploited — CISA orders federal agencies to patch Two critical bugs (CVE-2026-72529 and CVE-2026-72530) allow remote code execution without authentication. Attackers have used them to replace client installers and push malware to meeting participants. Federal remediation deadlines are already in effect. 3. GitLab critical flaw hit by active exploitation within days of disclosure CVE-2026-19478 lets unauthenticated attackers modify or delete public projects through GraphQL. Affected versions should be updated immediately or public repository access restricted as a temporary measure. 4. Suspected Russian clusters abuse Google OAuth and WhatsApp linking Three threat groups are targeting academics, defense and government personnel in Europe and the US with sophisticated phishing that leverages legitimate authentication flows and device pairing to hijack accounts. 5. Malicious Rust crates deliver build-time malware Compromised versions of popular crates (hundreds of millions of downloads) briefly executed remote payloads during compilation. The packages were yanked quickly, but the incident underscores ongoing supply-chain risks for developers. #Cybersecurity #CISA #NIST

    Post summary

    The bulletin reports that CVE‑2026‑73570, CVE‑2026‑72529/30, and CVE‑2026‑19478 are actively exploited, urging operators to verify patches and apply updates immediately.

    10000102
    74 followersView on X
  • Zero Hunt@zerohuntai
    Active Exploitation

    Your on-prem video server just became the malware. Head Mare chained two unauth bugs in TrueConf Server — CVE-2026-72529 (RCE) + CVE-2026-72530 (sandbox escape) — to SYSTEM, then swapped the client installer every employee downloads. CISA KEV'd both Aug 20. 🧵 1/5

    Post summary

    CISA designated both CVE-2026-72529 and CVE-2026-72530 as KEVs in August, indicating they are actively exploited. The advisory details the vulnerabilities (RCE and sandbox escape) but lacks patch info or PoC.

    1000045
    16 followersView on X
  • CVE Brief@DailyCVEBrief
    Disclosure

    DEEP DIVE — CVE-2026-72529: unauthenticated script execution in TrueConf Server over TCP/4307 (CVSS 9.8), chained with CVE-2026-72530 to reach SYSTEM. KEV-listed with a 3-day deadline. The patch shipped in June, two months before the CVE ID was published. https://t.co/7yEhqCcwUa

    Post summary

    The tweet discloses technical details of CVE-2026-72529, notes its KEV status and that a patch was already available, but does not indicate active exploitation or a proof‑of‑concept.

    1000041
    29 followersView on X
  • Divinmentis@Divinmentis
    Patch

    CVE-2026-72529 and CVE-2026-72530 affect older TrueConf Server 5.3, 5.4 and 5.5 builds. The Canadian Cyber Centre lists fixed versions as 5.3.9, 5.4.9 and 5.5.5 or later. https://t.co/wH8tAClUJt

    Post summary

    The Canadian Cyber Centre announced patch releases (5.3.9, 5.4.9, 5.5.5) for CVE‑2026‑72529 and CVE‑2026‑72530 affecting older TrueConf Server builds, with no proof‑of‑concept, exploit, or active exploitation noted.

    1000023
    53 followersView on X
  • AlexAImaginator@TraffAlex
    Active Exploitation

    🔒 CYBERSECURITY, PRIVACY & OPEN SOURCE ROUNDUP — August 21, 2026 1️⃣ MICROSOFT ENTRA ID: CVSS 10.0 RCE EXPLOITED IN THE WILD, FIXED SILENTLY Microsoft disclosed that CVE-2026-69836, a critical remote code execution flaw in Microsoft Entra ID rated CVSS 10.0, was exploited in the wild. The bug stems from deserialization of untrusted data and could allow an unauthenticated attacker to run code against the identity platform underpinning Microsoft 365, Azure, and countless third-party applications. The twist: Microsoft has already fully mitigated it server-side, so no client patch or administrator action is required. Threat teams are still advised to review Entra logs for suspicious app registrations, new credentials, and unexpected service-principal changes during the window before the fix landed. 🔹 @socradar 2️⃣ NORTH KOREA'S SAPPHIRE SLEET POISONS http://CRATES.IO RUST SUPPLY CHAIN A North Korean APT group tracked as Sapphire Sleet compromised a legitimate crates DOT io maintainer account on August 20 and pushed a poisoned arrayref release, followed within twenty minutes by tainted versions of two other crates owned by the same maintainer. The payload rode on a lookalike package impersonating proc-macro2, hiding a build script that disabled TLS certificate validation and attempted to fetch a platform-specific second-stage binary. The Rust Security Response Team took the packages down in roughly 86 minutes and reports no evidence of downstream use — but arrayref alone has over 245 million downloads and appears in about three-quarters of Rust environments, and Wiz linked the campaign to earlier NPM supply-chain operations. 🔹 @DFIR_Radar 3️⃣ RUSSIAN ESPIONAGE CLUSTERS HIJACK GOOGLE, MICROSOFT & WHATSAPP VIA OAUTH Suspected Russian espionage groups UNC6293, UNC5976, and UNC7005 have been abusing legitimate authentication flows — OAuth phishing, app passwords, device codes, and WhatsApp device linking — to take over accounts at government, defense, academic, and think-tank targets. Instead of brute force, the campaigns walk victims through genuine-looking login pages to steal tokens, or trick them into pairing attacker-controlled devices. A quiet reminder that identity is now the primary attack surface: the phishing page can be real and still be a weapon. 🔹 @Huntio 4️⃣ APOLLO CONFIRMS CLOUD DATA BREACH AMID PE EXTORPTION WAVE Private equity giant Apollo Global Management has confirmed that hackers stole a large volume of personal data from its cloud environment between July 6 and July 10, according to a filing with California's attorney general. Stolen data includes names, dates of birth, contact details with home addresses, and Social Security numbers. The incident fits a pattern Google researchers warned about last month: social-engineering extortion campaigns operating under names such as Falcon, Helix, Pink, and Redact, which trick employees into surrendering passwords and MFA codes at spoofed helpdesk portals — with reported ransoms reaching $750,000 per victim. 🔹 @aarnyc 5️⃣ CISA ADDS TRUECONF VULNS TO KEV CATALOG CISA has added two TrueConf Server vulnerabilities — CVE-2026-72529 and CVE-2026-72530 — to its Known Exploited Vulnerabilities catalog. A KEV listing signals confirmed real-world exploitation and sets a remediation deadline for federal agencies, and it should be read by every organization running TrueConf as an instruction to patch immediately rather than at the next convenient maintenance window. 🔹 @VettedSecOps 6️⃣ MACSYNC STEALER: NEW MAC INFOSTEALER TARGETS DEV & CLOUD CREDENTIALS Microsoft is reporting a new macOS infostealer called MacSync Stealer that, using ClickFix-style social engineering at the terminal, harvests Keychain contents, browser credentials, SSH keys, AWS credentials, and Kubernetes configuration files, then exfiltrates the loot in chunked curl PUT requests. The tooling is aimed squarely at developers and cloud operators — the highest-value targets for stolen credentials. 🔹 @CTITraffic 7️⃣ CHAT CONTROL 1.0 SURVIVES DESPITE MEP MAJORITY VOTING AGAINST The Chat Control 1.0 message-scanning regime remains in force after the European Parliament failed to block its extension on July 9. The procedural wrinkle: 314 MEPs voted against and 276 in favor — yet rejection required an absolute majority of 361, so the opposition fell 47 votes short and the regime continues through 2028. A stark case study in how procedure can override a visible majority vote, and the reason privacy advocates keep pushing for binding votes on surveillance measures. 🔹 @frankcorva 8️⃣ CISA SHIPS K-12 CYBERSECURITY FOUNDATIONS PACKAGE CISA released a new resource package with cybersecurity foundations for K-12 schools and districts, bundling practical steps schools can take right away to reduce risk and harden their defenses. A useful baseline for the education sector, which is often under-resourced and a favorite target for student and family data. 🔹 @CISAgov 💭 The through-line this week is familiar but worth repeating: the most damaging compromises did not start at an unpatched server — they started with a stolen identity, a hijacked maintainer account, or a convincing phone call. Patching still matters, but identity hygiene, supply-chain verification, and healthy suspicion of every "helpdesk" request matter just as much. The organizations that get hit are rarely the ones that did nothing; they are the ones that did almost everything. Which of these is the most underappreciated risk right now — the silent Entra fix, Rust supply chains, or OAuth-based account hijacking? 👇 #CyberSecurity #DataBreach #OpenSource

    Post summary

    The roundup confirms that CVE‑2026‑69836 has been exploited in the wild and has already been mitigated server‑side, while other CVEs on the KEV list also signify real‑world attacks, underscoring the urgent need for patching and monitoring.

    00010420
    2.7K followersView on X
  • NewNormal Security@NewScanTeam
    Active Exploitation

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 21 Aug 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 📦 Actively-exploited build of a self-hosted conferencing server — code execution and account takeover with no login (TrueConf CVE-2026-72530, CVE-2026-72529) 🔓 API guard that reads a different path than the router — a re-spelled URL skips it and hands over every message in a dev mail catcher, password resets included (Mailpit CVE-2026-67448) ⚡ CMS mis-reading PHP open tags in user-supplied content, exploited in the wild this month — unauthenticated code execution (SPIP CVE-2026-77647) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #RCE #CSO #REDTEAM

    Post summary

    NewNormal Security reports that several CVEs are being actively exploited in the wild, providing brief technical details such as code execution and account takeover scenarios.

    0001037
    5 followersView on X
  • SecAlerts@SecAlertsCo
    Active Exploitation

    🔓 EXPLOITED: CVE-2026-72529 in TrueConf Server. No auth needed — attackers hit port 4307/TCP to execute arbitrary scripts. CISA KEV-listed. Versions 5.3.x-5.5.5 affected. Patch now. #cybersecurity #ciso #vulnerabilities #mssp https://secalerts.co/vulnerability/CVE-2026-72529?utm_campaign=x https://t.co/xsINZq21aG

    Post summary

    CVE-2026-72529 in TrueConf Server is actively exploited via port 4307/TCP without authentication; the vulnerability is CISA KEV‑listed and a patch has been released.

    00010131
    878 followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(08/20追加) 🛡CVE-2026-72529 TrueConf Server Missing Authentication for Critical Function Vulnerability ✅概要 ・深刻度:緊急 9.3 (CVSS Base) / Kaspersky (CNA) ・種別:重要な機能に対する認証の欠如 (CWE-306) ・CVSS:CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N TrueConf Server に存在する、重要な機能に対する認証の欠如の脆弱性です。 未認証のリモート攻撃者が 4307/TCP 経由で未文書化の機能を呼び出すことで、サーバー上で任意のスクリプトを実行できる可能性があります。 5.3.9、5.4.9、5.5.5 で修正されています。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年8月23日 ・BOD 26-04 対処期限(露出なし):2026年8月23日 ✅攻撃前提条件 ・TrueConf Server の影響を受けるバージョンを使用している ・5.3 系では 5.3.9 未満、5.4 系では 5.4.9 未満、5.5 系では 5.5.5 未満、または 5.3 未満を使用している ・攻撃者が対象サーバーの 4307/TCP へネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・修正済みバージョンへ更新されていない ✅悪用時影響 ・未認証の攻撃者に任意のスクリプトを実行される可能性がある ・TrueConf Server の処理を不正に実行される可能性がある ・サーバー上の情報へ不正アクセスされる可能性がある ・データの改ざんやサービスの可用性に影響が生じる可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(Kaspersky) ・概要:Kaspersky は、Head Mare が KLCERT-26-057 を含む TrueConf Server の脆弱性チェーンを悪用した2026年7月の攻撃を確認し、公表しています。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-72529 ・https://ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-missing-authentication-for-critical-function/ ・https://trueconf.com/blog/update/trueconf-server-security-updates-june-2026 ・https://github.com/cisagov/vulnrichment/blob/develop/2026/72xxx/CVE-2026-72529.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-72529 ・https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/ ・https://www.ipa.go.jp/security/vuln/scap/cwe.html ・https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk 🛡CVE-2026-72530 TrueConf Server Code Injection Vulnerability ✅概要 ・深刻度:緊急 9.5 (CVSS Base) / Kaspersky (CNA) ・種別:コード・インジェクション (CWE-94) ・CVSS:CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H TrueConf Server に存在するコード・インジェクションの脆弱性です。 未認証のリモート攻撃者が 4307/TCP 経由で細工したスクリプトを使用することで、隔離環境を突破し、ホストシステム上で任意のコードを実行できる可能性があります。 5.3.9、5.4.9、5.5.5 で修正されています。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅CISA 評価 ・攻撃自動化:自動化は困難 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年8月23日 ・BOD 26-04 対処期限(露出なし):2026年9月3日 ✅攻撃前提条件 ・TrueConf Server の影響を受けるバージョンを使用している ・5.3 系では 5.3.9 未満、5.4 系では 5.4.9 未満、5.5 系では 5.5.5 未満、または 5.3 未満を使用している ・攻撃者が対象サーバーの 4307/TCP へネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・細工したスクリプトを隔離環境内で実行可能な状態である ・修正済みバージョンへ更新されていない ✅悪用時影響 ・TrueConf Server の隔離環境を突破される可能性がある ・ホストシステム上で任意のコードを実行される可能性がある ・ホストシステム上の情報へ不正アクセスされる可能性がある ・ホストシステムのデータを改ざんされる可能性がある ・機密性、完全性、可用性に高い影響が生じる可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(Kaspersky) ・概要:Kaspersky は、Head Mare が KLCERT-26-058 を含む TrueConf Server の脆弱性チェーンを悪用した2026年7月の攻撃を確認し、公表しています。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-72530 ・https://ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-breakout-from-isolated-environment/ ・https://trueconf.com/blog/update/trueconf-server-security-updates-june-2026 ・https://github.com/cisagov/vulnrichment/blob/develop/2026/72xxx/CVE-2026-72530.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-72530 ・https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/ ・https://www.ipa.go.jp/security/vuln/scap/cwe.html ・https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk CISA Alert ・https://www.cisa.gov/news-events/alerts/2026/08/20/cisa-adds-one-known-exploited-vulnerability-catalog #vulnerability

    Post summary

    The post confirms that CVE‑2026‑72529 and CVE‑2026‑72530 have been actively exploited by Head Mare in July 2026, provides patch information, and references technical details, underscoring an active exploitation scenario.

    000104.8K
    44.1K followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISAが既知の悪用された脆弱性2件をカタログに追加 CISA Adds Two Known Exploited Vulnerabilities to Catalog #CISA (Aug 20) CVE-2026-72529 TrueConfサーバーの重要な機能に対する認証の欠如の脆弱性 CVE-2026-72530 TrueConfサーバーのコードインジェクション脆弱性 https://www.cisa.gov/news-events/alerts/2026/08/20/cisa-adds-two-known-exploited-vulnerabilities-catalog

    Post summary

    CISA announces the addition of two CVEs—CVE-2026-72529 (auth bypass) and CVE-2026-72530 (code injection) in TrueConf servers—to its catalog of known exploited vulnerabilities, highlighting active exploitation but not yet providing patches or PoC details.

    00010252
    4.9K followersView on X
  • NotCVE@notCVE
    Active Exploitation

    ⚠️ ACTIVELY EXPLOITED — added to CISA KEV 2026-08-20 CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability CVSS 9.8 · EPSS 0.3% · 4 public exploits Details, versions & intel → https://notcve.org/cve/CVE-2026-72529 https://t.co/OElkvM3XWP

    Post summary

    The CVE-2026-72529 is confirmed to be actively exploited, with multiple public exploits and inclusion in the CISA KEV, but no PoC, exploit code, or patch is mentioned.

    1000095
    68 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apptrueconftrueconf_server-linux_kernel-
Apptrueconftrueconf_server-windows-

Explore more