Ukrainian hacktivists exploiting the bugs, but TrueConf's reach stretches well beyond home turf
CISA has ordered US federal agencies to patch two exploited flaws in TrueConf, a Russian-built video conferencing platform, after compromised servers were caught handing malware to unsuspecting meeting participants.The US cybersecurity agency on Thursday added CVE-2026-72529 and CVE-2026-72530 to its Known Exploited Vulnerabilities catalog, saying both have been used in real-world attacks. What CISA doesn't say is who is being attacked, or where.The only publicly documented attacks exploiting these two bugs so far come from Kaspersky, which linked them to Head Mare, a pro-Ukrainian hacktivist group that has repeatedly gone after Russian organizations. Its latest campaign targeted Russian companies across industries including transport, energy, electronics, IT, and software development.
CISA doesn't say whether it added the flaws to KEV because of those attacks or because it has evidence of exploitation elsewhere, potentially including against organizations in the US.
That question is particularly interesting given what TrueConf is and who uses it.TrueConf is a Moscow-based maker of video conferencing software that offers an on-premises alternative to cloud services such as Zoom and Microsoft Teams. Organizations can run TrueConf Server on their own infrastructure, including in private networks, giving them control over where their calls and associated data go.









