⚠️ Hackers breached TrueConf servers across Russia.
PhantomCore chained 3 privately developed bugs to skip login, run commands, and move inside networks. Attacks started weeks after patches.
🔗 See how the attacks worked → thehackernews.com/2026/04/ph…
Recently, I have heard about a TrueConf vulnerability to be added to the CISA KEV on @riskybusiness and frankly it made me stop running and laugh for a few seconds. I had to rewind and listen to it once again to believe that. Then I had to write up why: arunninghacker.substack.com/…
The latest threat activity reveals a clear pattern the most trusted systems are now the most targeted. This week’s developments show attackers focusing on enterprise platforms that sit at the core of business operations endpoint management systems, remote access solutions, collaboration tools, and even developer workflows.
𝗞𝗲𝘆 𝗱𝗲𝘃𝗲𝗹𝗼𝗽𝗺𝗲𝗻𝘁𝘀 𝗼𝗳 𝘄𝗲𝗲𝗸:
🔹3 vulnerabilities added to the CISA KEV catalog
🔹Active exploitation detected in Tianxin Internet Behavior Management System, Flowise AI, Ninja Forms - File Upload WordPress plugin
🔹Microsoft Warns of high-velocity Medusa Ransomware attacks targeting global sectors
🔹NCSC Warns of Router Exploitation and Credential Theft via Malicious DNS Infrastructure
Know more : loginsoft.com/reports/weekly…
Stay safe and secured with Loginsoft Vulnerability Intelligence
#Cybersecurity#Loginsoft#LOVI#Vulnerability#Intelligence#InfoSec#CISAKEV#ActiveExploits#ThreatIntel#Tianxin#NinjaForms#Microsoft#Medusa#Ransomware#Storm_1175#FlowiseAI#Fortinet#TrueConf
📌 CISA تدرج ثغرة TrueConf ضمن قائمة KEV إثر استغلالها الفعّال
أدرجت وكالة الأمن السيبراني والبنية التحتية (CISA) ثغرة أمنية حرجة، المحددة بـ CVE-2026-3502، والتي تؤثر على برنامج TrueConf، ضمن قائمة الثغرات المستغلة المعروفة (KEV). يأتي هذا الإدراج تأكيداً على استغلال الثغرة فعلياً في الهجمات السيبرانية، مما يستدعي اهتماماً فورياً من المؤسسات التي تستخدم برنامج TrueConf. نظراً للمخاطر العالية التي تشكلها الثغرات المستغلة، يُنصح بشدة بتطبيق التحديثات الأمنية المتاحة بشكل عاجل لتقليل نوافذ الهجوم.
🔗 للمزيد: cybersecuritynews.com/cisa-t…
A bug in TrueConf video conferencing software is being exploited by hackers, prompting the U.S. government to order all agencies to patch the vulnerability within two weeks therecord.media/trueconf-cyb…
Critical TrueConf flaw CVE-2026-3502 allows state-backed actors to hijack updates and infect air-gapped networks. Update to version 8.5.3 now to stay secure.
meterpreter.org/the-trojan-m…
🛡️ We added TrueConf Client download of code without integrity check vulnerability CVE-2026-3502 to our Known Exploited Vulnerabilities Catalog. Visit go.dhs.gov/Z3Q for more information. #Cybersecurity#InfoSec