Exploitation observed; activity peaked at 18 mentions and remains active
Immediate actions
Patch trueconf trueconf_server systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-08-23. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
⚠️⚠️ CVE-2026-72529 (CVSS 9.8) + CVE-2026-72530 (CVSS 9.0): Unauthenticated RCE in TrueConf Server
🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJUcnVlQ29uZi1WQ1Mi
🎯2.9K+ Results are found on http://en.fofa.info in the past year.
FOFA Query: app="TrueConf-VCS"
🔖Refer: https://www.scworld.com/news/trueconf-flaws-enabling-attacks-on-meeting-participants-added-to-kev-catalog
#OSINT#FOFA#CyberSecurity#Vulnerability
Post summary
The tweet announces the discovery of two high‑severity CVEs for TrueConf Server, providing technical details and referencing external security resources, but offers no PoC, exploit code, active exploitation evidence, or patch information.
🛡️We added TrueConf Server vulnerabilities CVE-2026-72529 & CVE-2026-72530 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity#InfoSec https://t.co/dzrodjLszP
Post summary
The DHS alert adds TrueConf Server CVE‑2026‑72529 and CVE‑2026‑72530 to its catalog of known exploited vulnerabilities, urges organizations to apply mitigations, and signals that these weaknesses are being actively attacked.
Actively exploited vulnerabilities CVE-2026-72529 and CVE-2026-72530 pose severe risks to federal systems. More details: https://cnews.link/trueconf-vulnerability-cisa-warning-3/ https://t.co/rWDqEhCMAW
Post summary
The post states that CVE-2026-72529 and CVE-2026-72530 are currently being exploited, posing severe risks to federal systems.
@anton_chuvakin One example – CVE-2026-72529 (unauth RCE):
Exploitation discovered in June, fixed in June. Five urgent comms to update ASAP.
* Two months later *
CVE ID assigned in August. Listed in CISA KEV in August. 3-day patch deadline.
The article primarily reports vendor patch releases and evidence of active exploitation, with detailed technical information about the identified vulnerabilities.
🚨 CVE-of-the-Day: CVE-2026-72529 — TrueConf Server unauthenticated RCE via missing auth on port 4307, actively exploited
CVSS: 9.8 | EPSS: 0.3%
Unauthenticated attackers with network access to TCP/4307 can invoke an undocumented critical function and execute arbitrary scripts. Often chained with CVE-2026-72530 for full host takeover.
#CVE#infosec
Post summary
The tweet announces CVE-2026-72529 as an unauthenticated RCE in TrueConf Server (port 4307, CVSS 9.8) claimed to be actively exploited, often chained with CVE-2026-72530, but provides no patch, workaround, or PoC reference.
Warning: Critical Missing Authentication and Code Injection vulnerabilities in #TrueConfServer. CVE-2026-72529 CVSS: 9.3 / CVE-2026-72530 CVSS: 9.5. This actively exploited vulnerability chain results in remote code execution #RCE! Time to #Patch#Patch#Patch
Post summary
The post warns of two critical, actively exploited vulnerabilities in TrueConfServer (CVE-2026-72529 and CVE-2026-72530) that enable remote code execution and urges immediate patching.
CISA confirms two TrueConf Server flaws, CVE-2026-72529 and CVE-2026-72530, are exploited in the wild to deliver PhantomCore malware. Patch now.
#TrueConf#CVE#ExploitedInTheWild#PhantomCore#HeadMare#InfoSec#PatchNow
https://securityonline.info/trueconf-cve-2026-72529-exploited/
Post summary
CISA confirms that the two TrueConf Server CVEs are being actively exploited in the wild to deliver PhantomCore malware, and urges immediate patching.
🛡️ CYBER BULLETIN | 2026/08/23 🚨
1. CISA flags actively exploited TrueConf Server flaws
Two critical vulnerabilities in the self-hosted video platform (CVE-2026-72529 and CVE-2026-72530) landed in CISA’s KEV catalog. Attackers with network access can run arbitrary code; the Head Mare group has already used them to push malware. Federal agencies must patch ASAP.
2. Critical GitLab GraphQL bug under active exploitation
CVE-2026-19478 (CVSS 9.4) lets unauthenticated attackers modify or delete public projects via a crafted GraphQL directive. Disclosed and patched mid-week, exploitation attempts hit honeypots within days. Self-managed instances need the latest updates now.
3. Microsoft Defender’s own driver can delete security software
Check Point Research showed how the legitimate, signed BTR.sys boot-time remediation driver can be repurposed for kernel-level file and registry ops—enough to wipe AV/EDR components before they start. No real-world abuse seen yet, but the technique works across Windows 7 to 11 25H2.
4. Trojanized npm packages deliver AI-powered Linux backdoor
Fourteen packages posing as harmless calendar/streak tools drop RedC2 4.0’s RedShell implant the moment they’re imported. The framework includes an LLM agent that turns natural-language commands into post-exploitation actions. Classic supply-chain risk for developers.
#Cybersecurity#CISA#NIST
Post summary
Two critical CVEs (CVE‑2026‑72529/72530 and CVE‑2026‑19478) are actively exploited in the wild, with vendors urging immediate patching, while a new supply‑chain backdoor appears but has not yet been observed in real‑world abuse.
IT/security teams running self-hosted TrueConf Server: patch now. CISA added CVE-2026-72529 and CVE-2026-72530 to KEV after active exploitation. Federal deadline: Sept. 3. Is TCP 4307 exposed? https://t.co/kJdtqYwCRA
Post summary
CISA has added CVE‑2026‑72529 and CVE‑2026‑72530 to its KEV list after active exploitation, urging IT/security teams to patch TrueConf Server before the September 3 federal deadline.
🛡️ CYBER BULLETIN | 2026/08/22 🚨
1. CISA adds Zimbra OS command injection to KEV catalog
CVE-2026-73570 is under active exploitation. Unauthenticated attackers can execute commands as the Zimbra user via crafted SMTP requests when SNMP notifications are enabled. Email server operators should verify patches and check logs for signs of compromise.
2. TrueConf Server flaws actively exploited — CISA orders federal agencies to patch
Two critical bugs (CVE-2026-72529 and CVE-2026-72530) allow remote code execution without authentication. Attackers have used them to replace client installers and push malware to meeting participants. Federal remediation deadlines are already in effect.
3. GitLab critical flaw hit by active exploitation within days of disclosure
CVE-2026-19478 lets unauthenticated attackers modify or delete public projects through GraphQL. Affected versions should be updated immediately or public repository access restricted as a temporary measure.
4. Suspected Russian clusters abuse Google OAuth and WhatsApp linking
Three threat groups are targeting academics, defense and government personnel in Europe and the US with sophisticated phishing that leverages legitimate authentication flows and device pairing to hijack accounts.
5. Malicious Rust crates deliver build-time malware
Compromised versions of popular crates (hundreds of millions of downloads) briefly executed remote payloads during compilation. The packages were yanked quickly, but the incident underscores ongoing supply-chain risks for developers.
#Cybersecurity#CISA#NIST
Post summary
The bulletin reports that CVE‑2026‑73570, CVE‑2026‑72529/30, and CVE‑2026‑19478 are actively exploited, urging operators to verify patches and apply updates immediately.
Your on-prem video server just became the malware.
Head Mare chained two unauth bugs in TrueConf Server — CVE-2026-72529 (RCE) + CVE-2026-72530 (sandbox escape) — to SYSTEM, then swapped the client installer every employee downloads.
CISA KEV'd both Aug 20.
🧵 1/5
Post summary
CISA designated both CVE-2026-72529 and CVE-2026-72530 as KEVs in August, indicating they are actively exploited. The advisory details the vulnerabilities (RCE and sandbox escape) but lacks patch info or PoC.
DEEP DIVE — CVE-2026-72529: unauthenticated script execution in TrueConf Server over TCP/4307 (CVSS 9.8), chained with CVE-2026-72530 to reach SYSTEM. KEV-listed with a 3-day deadline. The patch shipped in June, two months before the CVE ID was published. https://t.co/7yEhqCcwUa
Post summary
The tweet discloses technical details of CVE-2026-72529, notes its KEV status and that a patch was already available, but does not indicate active exploitation or a proof‑of‑concept.
CVE-2026-72529 and CVE-2026-72530 affect older TrueConf Server 5.3, 5.4 and 5.5 builds. The Canadian Cyber Centre lists fixed versions as 5.3.9, 5.4.9 and 5.5.5 or later. https://t.co/wH8tAClUJt
Post summary
The Canadian Cyber Centre announced patch releases (5.3.9, 5.4.9, 5.5.5) for CVE‑2026‑72529 and CVE‑2026‑72530 affecting older TrueConf Server builds, with no proof‑of‑concept, exploit, or active exploitation noted.
🔒 CYBERSECURITY, PRIVACY & OPEN SOURCE ROUNDUP — August 21, 2026
1️⃣ MICROSOFT ENTRA ID: CVSS 10.0 RCE EXPLOITED IN THE WILD, FIXED SILENTLY
Microsoft disclosed that CVE-2026-69836, a critical remote code execution flaw in Microsoft Entra ID rated CVSS 10.0, was exploited in the wild. The bug stems from deserialization of untrusted data and could allow an unauthenticated attacker to run code against the identity platform underpinning Microsoft 365, Azure, and countless third-party applications. The twist: Microsoft has already fully mitigated it server-side, so no client patch or administrator action is required. Threat teams are still advised to review Entra logs for suspicious app registrations, new credentials, and unexpected service-principal changes during the window before the fix landed.
🔹 @socradar
2️⃣ NORTH KOREA'S SAPPHIRE SLEET POISONS http://CRATES.IO RUST SUPPLY CHAIN
A North Korean APT group tracked as Sapphire Sleet compromised a legitimate crates DOT io maintainer account on August 20 and pushed a poisoned arrayref release, followed within twenty minutes by tainted versions of two other crates owned by the same maintainer. The payload rode on a lookalike package impersonating proc-macro2, hiding a build script that disabled TLS certificate validation and attempted to fetch a platform-specific second-stage binary. The Rust Security Response Team took the packages down in roughly 86 minutes and reports no evidence of downstream use — but arrayref alone has over 245 million downloads and appears in about three-quarters of Rust environments, and Wiz linked the campaign to earlier NPM supply-chain operations.
🔹 @DFIR_Radar
3️⃣ RUSSIAN ESPIONAGE CLUSTERS HIJACK GOOGLE, MICROSOFT & WHATSAPP VIA OAUTH
Suspected Russian espionage groups UNC6293, UNC5976, and UNC7005 have been abusing legitimate authentication flows — OAuth phishing, app passwords, device codes, and WhatsApp device linking — to take over accounts at government, defense, academic, and think-tank targets. Instead of brute force, the campaigns walk victims through genuine-looking login pages to steal tokens, or trick them into pairing attacker-controlled devices. A quiet reminder that identity is now the primary attack surface: the phishing page can be real and still be a weapon.
🔹 @Huntio
4️⃣ APOLLO CONFIRMS CLOUD DATA BREACH AMID PE EXTORPTION WAVE
Private equity giant Apollo Global Management has confirmed that hackers stole a large volume of personal data from its cloud environment between July 6 and July 10, according to a filing with California's attorney general. Stolen data includes names, dates of birth, contact details with home addresses, and Social Security numbers. The incident fits a pattern Google researchers warned about last month: social-engineering extortion campaigns operating under names such as Falcon, Helix, Pink, and Redact, which trick employees into surrendering passwords and MFA codes at spoofed helpdesk portals — with reported ransoms reaching $750,000 per victim.
🔹 @aarnyc
5️⃣ CISA ADDS TRUECONF VULNS TO KEV CATALOG
CISA has added two TrueConf Server vulnerabilities — CVE-2026-72529 and CVE-2026-72530 — to its Known Exploited Vulnerabilities catalog. A KEV listing signals confirmed real-world exploitation and sets a remediation deadline for federal agencies, and it should be read by every organization running TrueConf as an instruction to patch immediately rather than at the next convenient maintenance window.
🔹 @VettedSecOps
6️⃣ MACSYNC STEALER: NEW MAC INFOSTEALER TARGETS DEV & CLOUD CREDENTIALS
Microsoft is reporting a new macOS infostealer called MacSync Stealer that, using ClickFix-style social engineering at the terminal, harvests Keychain contents, browser credentials, SSH keys, AWS credentials, and Kubernetes configuration files, then exfiltrates the loot in chunked curl PUT requests. The tooling is aimed squarely at developers and cloud operators — the highest-value targets for stolen credentials.
🔹 @CTITraffic
7️⃣ CHAT CONTROL 1.0 SURVIVES DESPITE MEP MAJORITY VOTING AGAINST
The Chat Control 1.0 message-scanning regime remains in force after the European Parliament failed to block its extension on July 9. The procedural wrinkle: 314 MEPs voted against and 276 in favor — yet rejection required an absolute majority of 361, so the opposition fell 47 votes short and the regime continues through 2028. A stark case study in how procedure can override a visible majority vote, and the reason privacy advocates keep pushing for binding votes on surveillance measures.
🔹 @frankcorva
8️⃣ CISA SHIPS K-12 CYBERSECURITY FOUNDATIONS PACKAGE
CISA released a new resource package with cybersecurity foundations for K-12 schools and districts, bundling practical steps schools can take right away to reduce risk and harden their defenses. A useful baseline for the education sector, which is often under-resourced and a favorite target for student and family data.
🔹 @CISAgov
💭 The through-line this week is familiar but worth repeating: the most damaging compromises did not start at an unpatched server — they started with a stolen identity, a hijacked maintainer account, or a convincing phone call. Patching still matters, but identity hygiene, supply-chain verification, and healthy suspicion of every "helpdesk" request matter just as much. The organizations that get hit are rarely the ones that did nothing; they are the ones that did almost everything.
Which of these is the most underappreciated risk right now — the silent Entra fix, Rust supply chains, or OAuth-based account hijacking? 👇
#CyberSecurity#DataBreach#OpenSource
Post summary
The roundup confirms that CVE‑2026‑69836 has been exploited in the wild and has already been mitigated server‑side, while other CVEs on the KEV list also signify real‑world attacks, underscoring the urgent need for patching and monitoring.
NewNormal Security turns the last 24 hours of CVEs into new detections, every day.
𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 21 Aug 2026
𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆:
📦 Actively-exploited build of a self-hosted conferencing server — code execution and account takeover with no login (TrueConf CVE-2026-72530, CVE-2026-72529)
🔓 API guard that reads a different path than the router — a re-spelled URL skips it and hands over every message in a dev mail catcher, password resets included (Mailpit CVE-2026-67448)
⚡ CMS mis-reading PHP open tags in user-supplied content, exploited in the wild this month — unauthenticated code execution (SPIP CVE-2026-77647)
Test your stack with NewScan — free, self-hosted:
https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve
#infosec#AppSec#RCE#CSO#REDTEAM
Post summary
NewNormal Security reports that several CVEs are being actively exploited in the wild, providing brief technical details such as code execution and account takeover scenarios.
🔓 EXPLOITED: CVE-2026-72529 in TrueConf Server. No auth needed — attackers hit port 4307/TCP to execute arbitrary scripts. CISA KEV-listed. Versions 5.3.x-5.5.5 affected. Patch now.
#cybersecurity#ciso#vulnerabilities#mssp
https://secalerts.co/vulnerability/CVE-2026-72529?utm_campaign=x https://t.co/xsINZq21aG
Post summary
CVE-2026-72529 in TrueConf Server is actively exploited via port 4307/TCP without authentication; the vulnerability is CISA KEV‑listed and a patch has been released.
The post confirms that CVE‑2026‑72529 and CVE‑2026‑72530 have been actively exploited by Head Mare in July 2026, provides patch information, and references technical details, underscoring an active exploitation scenario.
CISAが既知の悪用された脆弱性2件をカタログに追加
CISA Adds Two Known Exploited Vulnerabilities to Catalog #CISA (Aug 20)
CVE-2026-72529 TrueConfサーバーの重要な機能に対する認証の欠如の脆弱性
CVE-2026-72530 TrueConfサーバーのコードインジェクション脆弱性
https://www.cisa.gov/news-events/alerts/2026/08/20/cisa-adds-two-known-exploited-vulnerabilities-catalog
Post summary
CISA announces the addition of two CVEs—CVE-2026-72529 (auth bypass) and CVE-2026-72530 (code injection) in TrueConf servers—to its catalog of known exploited vulnerabilities, highlighting active exploitation but not yet providing patches or PoC details.
⚠️ ACTIVELY EXPLOITED — added to CISA KEV 2026-08-20
CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability
CVSS 9.8 · EPSS 0.3% · 4 public exploits
Details, versions & intel → https://notcve.org/cve/CVE-2026-72529 https://t.co/OElkvM3XWP
Post summary
The CVE-2026-72529 is confirmed to be actively exploited, with multiple public exploits and inclusion in the CISA KEV, but no PoC, exploit code, or patch is mentioned.