‘By replacing legitimate update with malicious one, they turned product update flow into malware distribution channel’: Experts find flaw in TrueConf video conferencing tool used by governments, military



  • A sophisticated supply chain attack used the TrueConf update process
  • The Havoc framework is deployed for intelligence operations
  • The vulnerability is patched with the new version of TrueConf 8.5.3

Governments in Southeast Asia have recently been targeted in high-profile attacks as part of a wider cyber espionage campaign, which experts believe is the work of the Chinese government.

Security researchers Check Point detailed their findings in Operation TrueChaos, a campaign surrounding a zero-day vulnerability in TrueConf, a video conferencing and collaboration platform that runs in the cloud or on a company’s own servers.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

spot_img

More like this

NordVPN make Meshnet free to use

NordVPN promises urgent Mac app update after users call...

The latest NordVPN macOS update has caused significant interface lag and dropped connections for users.Frustrated customers took...
The Last of Us Part 2 Remastered Joel Miller looking up

A former Xbox boss thinks Naughty Dog’s decision to...

Former Microsoft executive Laura Fryer says Naughty Dog's decision to cancel The Last of Us Online ...
My New Ikea Smart Lamp is a Glowing Donut of Happiness

This Donut Smart Lamp From Ikea Has Super Bright...

Benefits ...