TrueConf Update Flaw Lets Attackers Reach Isolated Government Networks

TrueConf's self-hosted video conferencing servers have a zero-day flaw in their update mechanism that lets attackers replace legitimate updates with malicious executables. This bypasses endpoint defenses because the update process is trusted and automatic, allowing malware to run on all connected endpoints without triggering alerts. The vulnerability, tracked as CVE-2026-3502, affects TrueConf versions 8.1.0 through 8.5.2 and was fixed in 8.5.3. The threat actor TrueChaos has exploited this in attacks targeting government, defense, energy, and transportation sectors, including isolated environments. Indicators include files named poweriso.exe, 7z-x64.dll, iscsiexe.dll, and a suspicious update archive in %AppData%\Roaming\Adobe\update.7z. This vulnerability means that even air-gapped or isolated TrueConf environments are at risk because the trusted update channel itself is compromised. Endpoint defenses that rely on trust in update mechanisms will not detect this attack, increasing the risk of persistent, stealthy intrusions in critical sectors. Threat actors can maintain long-term access by abusing the update process.

Part of the PlainSec briefing for 2026-04-21

Sources