‘By replacing a legitimate update with a malicious one, they turned the product update flow into a malware distribution channel’: Experts find flaw in TrueConf video conferencing tool used by governments and military



  • Sophisticated supply chain attack exploited TrueConf update process
  • Havoc framework implemented for espionage operations
  • Vulnerability patched with new version 8.5.3 of TrueConf

Governments in Southeast Asia were recently the target of a highly sophisticated supply chain attack as part of a broader cyber espionage campaign, which experts believe is the work of the Chinese government.

Security researchers Check Point detailed their findings about Operation TrueChaos, a campaign that revolves around a zero-day vulnerability in TrueConf, a video conferencing and collaboration platform that runs in the cloud or on a company’s servers.



Leave a Comment

Your email address will not be published. Required fields are marked *