TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors. Russian cybersecurity vendor Kaspersky said it detected the attacks in July 2026. The activity involves exploiting a vulnerability chain
Security research like this is a reminder that visibility into endpoints, identity, and network traffic remains the foundation of any effective defense program.
Beyond patching, organizations should inventory exposed services, disable unused functionality, and require multi-factor authentication wherever it can be deployed.
Source: The Hacker News