๐จ ACTIVE EXPLOITATION
- Head Mare breaches TrueConf servers to trojanize client installers
Head Mare has compromised TrueConf servers to distribute backdoored client installers.
- TrueConf video conferencing server users are affected.
- Unpatched TrueConf servers are being compromised.
- Attackers replace legitimate client installers with malicious versions.
- The trojanized installers deliver backdoors. ๐ Coverage: bleepingcomputer.com ยท ๐ via BleepingComputer
๐ CVEs & KEV
- CVE-2026-64638 โ CVSS 8.9 โ New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP