Exploitation observed; activity peaked at 19 mentions and remains active
Immediate actions
Patch trueconf trueconf_server systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-09-03. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
⚠️⚠️ CVE-2026-72529 (CVSS 9.8) + CVE-2026-72530 (CVSS 9.0): Unauthenticated RCE in TrueConf Server
🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJUcnVlQ29uZi1WQ1Mi
🎯2.9K+ Results are found on http://en.fofa.info in the past year.
FOFA Query: app="TrueConf-VCS"
🔖Refer: https://www.scworld.com/news/trueconf-flaws-enabling-attacks-on-meeting-participants-added-to-kev-catalog
#OSINT#FOFA#CyberSecurity#Vulnerability
Post summary
The post announces two high‑severity, unauthenticated RCE vulnerabilities in TrueConf Server, providing CVE IDs, CVSS scores, and a KEV catalog reference, but it does not offer PoCs, exploit tools, or evidence of active exploitation.
🛡️We added TrueConf Server vulnerabilities CVE-2026-72529 & CVE-2026-72530 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity#InfoSec https://t.co/dzrodjLszP
Post summary
The DHS tweet announces that TrueConf Server vulnerabilities CVE-2026-72529 and CVE-2026-72530 are actively exploited, directs users to a link for mitigations, and urges organizations to implement protective measures.
Actively exploited vulnerabilities CVE-2026-72529 and CVE-2026-72530 pose severe risks to federal systems. More details: https://cnews.link/trueconf-vulnerability-cisa-warning-3/ https://t.co/rWDqEhCMAW
Post summary
The post announces that CVE‑2026‑72529 and CVE‑2026‑72530 are currently being actively exploited and pose severe risks to federal systems, though it provides no technical details or evidence of exploitation.
The post aggregates news about several recent CVE disclosures, noting available patches and confirming that some vulnerabilities are being actively exploited in the wild.
🚨 CVE-of-the-Day: CVE-2026-72529 — TrueConf Server unauthenticated RCE via missing auth on port 4307, actively exploited
CVSS: 9.8 | EPSS: 0.3%
Unauthenticated attackers with network access to TCP/4307 can invoke an undocumented critical function and execute arbitrary scripts. Often chained with CVE-2026-72530 for full host takeover.
#CVE#infosec
Post summary
The tweet announces CVE-2026-72529 as an unauthenticated RCE vulnerability in TrueConf Server on TCP/4307 with CVSS 9.8, explicitly stating it is being actively exploited in the wild and often chained with CVE-2026-72530 for full host compromise.
TrueConf Server に認証不要の任意コード実行(CVE-2026-72530・CVSS 9.0)。CISA KEV 収載済みで是正期限は9月3日です。4307/TCP の到達範囲の確認、系列ごとの修正版、侵害の見分け方までまとめました。
https://ai-news.autoarticles.net/article/post_1787491576433_w1fe8f
Post summary
The article announces a critical auth‑free RCE vulnerability (CVE‑2026‑72530) in TrueConf Server, notes its CISA KEV status, and provides information on patched versions and detection guidance.
Warning: Critical Missing Authentication and Code Injection vulnerabilities in #TrueConfServer. CVE-2026-72529 CVSS: 9.3 / CVE-2026-72530 CVSS: 9.5. This actively exploited vulnerability chain results in remote code execution #RCE! Time to #Patch#Patch#Patch
Post summary
The post alerts that CVE‑2026‑72529 and CVE‑2026‑72530 in TrueConfServer are actively exploited for remote code execution, urging users to patch immediately without providing any PoC or exploit tool.
CISA confirms two TrueConf Server flaws, CVE-2026-72529 and CVE-2026-72530, are exploited in the wild to deliver PhantomCore malware. Patch now.
#TrueConf#CVE#ExploitedInTheWild#PhantomCore#HeadMare#InfoSec#PatchNow
https://securityonline.info/trueconf-cve-2026-72529-exploited/
Post summary
CISA reports that CVE-2026-72529 and CVE-2026-72530 in TrueConf Server are actively exploited to deliver PhantomCore malware, and patches are now available.
🛡️ CYBER BULLETIN | 2026/08/23 🚨
1. CISA flags actively exploited TrueConf Server flaws
Two critical vulnerabilities in the self-hosted video platform (CVE-2026-72529 and CVE-2026-72530) landed in CISA’s KEV catalog. Attackers with network access can run arbitrary code; the Head Mare group has already used them to push malware. Federal agencies must patch ASAP.
2. Critical GitLab GraphQL bug under active exploitation
CVE-2026-19478 (CVSS 9.4) lets unauthenticated attackers modify or delete public projects via a crafted GraphQL directive. Disclosed and patched mid-week, exploitation attempts hit honeypots within days. Self-managed instances need the latest updates now.
3. Microsoft Defender’s own driver can delete security software
Check Point Research showed how the legitimate, signed BTR.sys boot-time remediation driver can be repurposed for kernel-level file and registry ops—enough to wipe AV/EDR components before they start. No real-world abuse seen yet, but the technique works across Windows 7 to 11 25H2.
4. Trojanized npm packages deliver AI-powered Linux backdoor
Fourteen packages posing as harmless calendar/streak tools drop RedC2 4.0’s RedShell implant the moment they’re imported. The framework includes an LLM agent that turns natural-language commands into post-exploitation actions. Classic supply-chain risk for developers.
#Cybersecurity#CISA#NIST
Post summary
The bulletin alerts that two critical vulnerabilities (CVE-2026-72529, CVE-2026-72530) in TrueConf Server and CVE-2026-19478 in GitLab are actively exploited in the wild, urging immediate patching of all affected systems.
IT/security teams running self-hosted TrueConf Server: patch now. CISA added CVE-2026-72529 and CVE-2026-72530 to KEV after active exploitation. Federal deadline: Sept. 3. Is TCP 4307 exposed? https://t.co/kJdtqYwCRA
Post summary
CISA has identified active exploitation of two TrueConf Server CVEs, prompting IT/security teams to patch by the federal deadline of September 3 to mitigate the risk.
🛡️ CYBER BULLETIN | 2026/08/22 🚨
1. CISA adds Zimbra OS command injection to KEV catalog
CVE-2026-73570 is under active exploitation. Unauthenticated attackers can execute commands as the Zimbra user via crafted SMTP requests when SNMP notifications are enabled. Email server operators should verify patches and check logs for signs of compromise.
2. TrueConf Server flaws actively exploited — CISA orders federal agencies to patch
Two critical bugs (CVE-2026-72529 and CVE-2026-72530) allow remote code execution without authentication. Attackers have used them to replace client installers and push malware to meeting participants. Federal remediation deadlines are already in effect.
3. GitLab critical flaw hit by active exploitation within days of disclosure
CVE-2026-19478 lets unauthenticated attackers modify or delete public projects through GraphQL. Affected versions should be updated immediately or public repository access restricted as a temporary measure.
4. Suspected Russian clusters abuse Google OAuth and WhatsApp linking
Three threat groups are targeting academics, defense and government personnel in Europe and the US with sophisticated phishing that leverages legitimate authentication flows and device pairing to hijack accounts.
5. Malicious Rust crates deliver build-time malware
Compromised versions of popular crates (hundreds of millions of downloads) briefly executed remote payloads during compilation. The packages were yanked quickly, but the incident underscores ongoing supply-chain risks for developers.
#Cybersecurity#CISA#NIST
Post summary
The bulletin warns that several high‑impact CVEs—Zimbra OS command injection, TrueConf Server RCE, and GitLab GraphQL manipulation—are actively exploited in the wild and urges immediate patching, monitoring, and federal remediation.
Your on-prem video server just became the malware.
Head Mare chained two unauth bugs in TrueConf Server — CVE-2026-72529 (RCE) + CVE-2026-72530 (sandbox escape) — to SYSTEM, then swapped the client installer every employee downloads.
CISA KEV'd both Aug 20.
🧵 1/5
Post summary
The excerpt reports that the two TrueConf Server CVEs (CVE‑2026‑72529 and CVE‑2026‑72530) have been actively exploited by chaining them to SYSTEM, with evidence of real‑world attacks and a CISA KEV listing.
PCMedicalist Signal · Aug 21
CVE-2026-72530--TrueConf Server Code: patch TrueConf Server Code and verify the fix held.
Full brief 👇 #CyberSecurity#Vulnerability#InfoSec
PCMedicalist · http://pcmedicalist.com/intel https://t.co/bSENpF1mPE
Post summary
The post announces that a patch has been applied to TrueConf Server Code for CVE-2026-72530 and invites verification, with no PoC, exploit code, or evidence of active exploitation.
DEEP DIVE — CVE-2026-72529: unauthenticated script execution in TrueConf Server over TCP/4307 (CVSS 9.8), chained with CVE-2026-72530 to reach SYSTEM. KEV-listed with a 3-day deadline. The patch shipped in June, two months before the CVE ID was published. https://t.co/7yEhqCcwUa
Post summary
The tweet provides a detailed disclosure of CVE‑2026‑72529, including technical exploitation vectors, a high CVSS score, active exploitation status, and notes that a patch was already released.
CVE-2026-72529 and CVE-2026-72530 affect older TrueConf Server 5.3, 5.4 and 5.5 builds. The Canadian Cyber Centre lists fixed versions as 5.3.9, 5.4.9 and 5.5.5 or later. https://t.co/wH8tAClUJt
Post summary
The post announces patch availability for CVE-2026-72529 and CVE-2026-72530 affecting older TrueConf Server builds, noting the fixed versions.
🔒 CYBERSECURITY, PRIVACY & OPEN SOURCE ROUNDUP — August 21, 2026
1️⃣ MICROSOFT ENTRA ID: CVSS 10.0 RCE EXPLOITED IN THE WILD, FIXED SILENTLY
Microsoft disclosed that CVE-2026-69836, a critical remote code execution flaw in Microsoft Entra ID rated CVSS 10.0, was exploited in the wild. The bug stems from deserialization of untrusted data and could allow an unauthenticated attacker to run code against the identity platform underpinning Microsoft 365, Azure, and countless third-party applications. The twist: Microsoft has already fully mitigated it server-side, so no client patch or administrator action is required. Threat teams are still advised to review Entra logs for suspicious app registrations, new credentials, and unexpected service-principal changes during the window before the fix landed.
🔹 @socradar
2️⃣ NORTH KOREA'S SAPPHIRE SLEET POISONS http://CRATES.IO RUST SUPPLY CHAIN
A North Korean APT group tracked as Sapphire Sleet compromised a legitimate crates DOT io maintainer account on August 20 and pushed a poisoned arrayref release, followed within twenty minutes by tainted versions of two other crates owned by the same maintainer. The payload rode on a lookalike package impersonating proc-macro2, hiding a build script that disabled TLS certificate validation and attempted to fetch a platform-specific second-stage binary. The Rust Security Response Team took the packages down in roughly 86 minutes and reports no evidence of downstream use — but arrayref alone has over 245 million downloads and appears in about three-quarters of Rust environments, and Wiz linked the campaign to earlier NPM supply-chain operations.
🔹 @DFIR_Radar
3️⃣ RUSSIAN ESPIONAGE CLUSTERS HIJACK GOOGLE, MICROSOFT & WHATSAPP VIA OAUTH
Suspected Russian espionage groups UNC6293, UNC5976, and UNC7005 have been abusing legitimate authentication flows — OAuth phishing, app passwords, device codes, and WhatsApp device linking — to take over accounts at government, defense, academic, and think-tank targets. Instead of brute force, the campaigns walk victims through genuine-looking login pages to steal tokens, or trick them into pairing attacker-controlled devices. A quiet reminder that identity is now the primary attack surface: the phishing page can be real and still be a weapon.
🔹 @Huntio
4️⃣ APOLLO CONFIRMS CLOUD DATA BREACH AMID PE EXTORPTION WAVE
Private equity giant Apollo Global Management has confirmed that hackers stole a large volume of personal data from its cloud environment between July 6 and July 10, according to a filing with California's attorney general. Stolen data includes names, dates of birth, contact details with home addresses, and Social Security numbers. The incident fits a pattern Google researchers warned about last month: social-engineering extortion campaigns operating under names such as Falcon, Helix, Pink, and Redact, which trick employees into surrendering passwords and MFA codes at spoofed helpdesk portals — with reported ransoms reaching $750,000 per victim.
🔹 @aarnyc
5️⃣ CISA ADDS TRUECONF VULNS TO KEV CATALOG
CISA has added two TrueConf Server vulnerabilities — CVE-2026-72529 and CVE-2026-72530 — to its Known Exploited Vulnerabilities catalog. A KEV listing signals confirmed real-world exploitation and sets a remediation deadline for federal agencies, and it should be read by every organization running TrueConf as an instruction to patch immediately rather than at the next convenient maintenance window.
🔹 @VettedSecOps
6️⃣ MACSYNC STEALER: NEW MAC INFOSTEALER TARGETS DEV & CLOUD CREDENTIALS
Microsoft is reporting a new macOS infostealer called MacSync Stealer that, using ClickFix-style social engineering at the terminal, harvests Keychain contents, browser credentials, SSH keys, AWS credentials, and Kubernetes configuration files, then exfiltrates the loot in chunked curl PUT requests. The tooling is aimed squarely at developers and cloud operators — the highest-value targets for stolen credentials.
🔹 @CTITraffic
7️⃣ CHAT CONTROL 1.0 SURVIVES DESPITE MEP MAJORITY VOTING AGAINST
The Chat Control 1.0 message-scanning regime remains in force after the European Parliament failed to block its extension on July 9. The procedural wrinkle: 314 MEPs voted against and 276 in favor — yet rejection required an absolute majority of 361, so the opposition fell 47 votes short and the regime continues through 2028. A stark case study in how procedure can override a visible majority vote, and the reason privacy advocates keep pushing for binding votes on surveillance measures.
🔹 @frankcorva
8️⃣ CISA SHIPS K-12 CYBERSECURITY FOUNDATIONS PACKAGE
CISA released a new resource package with cybersecurity foundations for K-12 schools and districts, bundling practical steps schools can take right away to reduce risk and harden their defenses. A useful baseline for the education sector, which is often under-resourced and a favorite target for student and family data.
🔹 @CISAgov
💭 The through-line this week is familiar but worth repeating: the most damaging compromises did not start at an unpatched server — they started with a stolen identity, a hijacked maintainer account, or a convincing phone call. Patching still matters, but identity hygiene, supply-chain verification, and healthy suspicion of every "helpdesk" request matter just as much. The organizations that get hit are rarely the ones that did nothing; they are the ones that did almost everything.
Which of these is the most underappreciated risk right now — the silent Entra fix, Rust supply chains, or OAuth-based account hijacking? 👇
#CyberSecurity#DataBreach#OpenSource
Post summary
The roundup focuses on CVE-2026-69836, a CVSS 10.0 RCE in Microsoft Entra ID that was actively exploited but silently fixed server‑side, and adds TrueConf vulnerabilities to the KEV catalog, underscoring real‑world exploitation and the need for immediate patching.
NewNormal Security turns the last 24 hours of CVEs into new detections, every day.
𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 21 Aug 2026
𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆:
📦 Actively-exploited build of a self-hosted conferencing server — code execution and account takeover with no login (TrueConf CVE-2026-72530, CVE-2026-72529)
🔓 API guard that reads a different path than the router — a re-spelled URL skips it and hands over every message in a dev mail catcher, password resets included (Mailpit CVE-2026-67448)
⚡ CMS mis-reading PHP open tags in user-supplied content, exploited in the wild this month — unauthenticated code execution (SPIP CVE-2026-77647)
Test your stack with NewScan — free, self-hosted:
https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve
#infosec#AppSec#RCE#CSO#REDTEAM
Post summary
The report highlights several CVEs that are actively exploited in the wild, detailing code execution and account takeover vectors, and promotes using NewScan for detection.
CISA added CVE-2026-72529 and CVE-2026-72530 to its known‑exploited vulnerable catalog, with Kaspersky reporting real‑world attacks in July 2026. Patch versions are available and brief technical details are provided.
CISAが既知の悪用された脆弱性2件をカタログに追加
CISA Adds Two Known Exploited Vulnerabilities to Catalog #CISA (Aug 20)
CVE-2026-72529 TrueConfサーバーの重要な機能に対する認証の欠如の脆弱性
CVE-2026-72530 TrueConfサーバーのコードインジェクション脆弱性
https://www.cisa.gov/news-events/alerts/2026/08/20/cisa-adds-two-known-exploited-vulnerabilities-catalog
Post summary
CISA has identified and cataloged two CVEs that are being actively exploited, urging organizations to remediate the vulnerabilities in TrueConf servers.
🚨 TrueConf Server RCE (CVE-2026-72529/CVE-2026-72530): exploited since July, CISA KEV Aug20, public PoC Aug26, PhantomCore delivered via fake client update. #TrueConf#RCE#CISAKEV
➡️ https://avleonov.com/2026/09/03/i146-about-remote-code-execution-trueconf-server-cve202672529-cve202672530-vulnerability/ https://t.co/lhpToTSVMG
Post summary
CVE-2026-72529 and CVE-2026-72530 involve remote code execution in TrueConf Server, have been actively exploited since July, are verified by CISA KEV, and a public PoC exists, though no patch has yet been disclosed.