CISA added CVE-2026-72529 and CVE-2026-72530 to its Known Exploited Vulnerabilities (KEV) catalog on Thursday, giving federal agencies until September 10 to patch the flaws. The bugs, exploited in tandem, allow unauthenticated attackers with network access to the default TCP port 4307 to execute arbitrary code on the underlying TrueConf server. Security firm Kaspersky attributed the initial exploits to Head Mare, a pro-Ukrainian hacktivist group that targeted Russian organizations across transport, energy, electronics, IT, and software development. The group used the access to replace legitimate TrueConf Windows client installers with trojanized versions carrying the PhantomCore backdoor, turning compromised servers into distribution points for malware. CISA did not confirm whether the exploitation extends to U.S. targets, but the agency's inclusion of the flaws in its KEV catalog suggests broader concern. TrueConf, a Moscow-based developer of on-premises video conferencing software, counts users in over 50 countries, including Switzerland’s Department of Justice and Istanbul Airport, though most customer references predate 2022.
In a separate but equally concerning campaign, researchers have identified a supply-chain attack targeting Android-based car head units. The attack uses a legitimate device-update application to spread malware that enlists compromised head units into a proxy botnet or uses them for ad fraud. The malware, delivered through a trojanized update, runs with elevated privileges and can execute arbitrary commands, potentially turning vehicles into unwitting nodes for malicious traffic. The attack's vector—abusing the update mechanism—mirrors the TrueConf compromise, where the installer itself was weaponized.
Additionally, cybersecurity firm ReliaQuest confirmed Friday that one of its employees was targeted in a social engineering attack after hackers impersonated a security team member. The attackers attempted to steal sensitive data but failed, according to the company. The incident follows a breach disclosure by ShinyHunters, which claimed to have accessed ReliaQuest's systems. ReliaQuest stated no customer data was compromised, but the attack underscores the increasing sophistication of impersonation campaigns.
CISA also reiterated its mandate for agencies to patch an actively exploited Zimbra Collaboration Suite vulnerability within three days, adding to the pressure on IT teams navigating a crowded patch cycle. TrueConf released fixes in versions 5.3.9, 5.4.9, and 5.5.5 on June 18. Administrators of both TrueConf and Zimbra are urged to prioritize updates given the potential for cascading compromises.