TrueConf Zero-Day Attack
What is the Attack? | Operation TrueChaos is a targeted cyber espionage campaign exploiting a zero-day vulnerability in the TrueConf video conferencing platform. The campaign primarily targets government entities in Southeast Asia by replacing a legitimate update with a malicious one. Threat actors effectively weaponized the product’s trusted update mechanism, transforming it into a covert malware distribution channel. |
What is the recommended Mitigation? |
|
What FortiGuard Coverage is available? |
|
Additional Resources
Operation TrueChaos Blog By Checkpoint
CISA Known Exploited Vulnerabilities Catalog