Vulnerabilità ed exploit · Exploit zero-day

TrueConf Update Flaw Lets Attackers Reach Isolated Government Networks

TrueConf's self-hosted video conferencing servers have a zero-day flaw in their update mechanism that lets attackers replace legitimate updates with malicious executables. This bypasses endpoint defenses because the update process is trusted and automatic, allowing malware to run on all connected endpoints without triggering alerts.

The vulnerability, tracked as CVE-2026-3502, affects TrueConf versions 8.1.0 through 8.5.2 and was fixed in 8.5.3. The threat actor TrueChaos has exploited this in attacks targeting government, defense, energy, and transportation sectors, including isolated environments. Indicators include files named poweriso.exe, 7z-x64.dll, iscsiexe.dll, and a suspicious update archive in %AppData%\Roaming\Adobe\update.7z.

This vulnerability means that even air-gapped or isolated TrueConf environments are at risk because the trusted update channel itself is compromised. Endpoint defenses that rely on trust in update mechanisms will not detect this attack, increasing the risk of persistent, stealthy intrusions in critical sectors. Threat actors can maintain long-term access by abusing the update process.

5 fonti · 3 apr

CVE-2026-3502

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 7.8 HIGH: trueConf Client downloads application update code and applies it without performing verification. EPSS 0.3% (23º percentile).

Data di correzione federale CISA 16 apr

Cronologia

Fonti

Part of the PlainSec briefing for 2026-03-31

Every edition of this story: TrueConf Update Flaw Lets Attackers Reach Isolated Government Networks

Altro da oggi