‘By replacing a legitimate update with a malicious one, they turned the product’s update flow into a malware distribution channel’: Experts find flaw in TrueConf video conferencing tool used by governments, military



  • Sophisticated supply chain attack exploited TrueConf update process
  • Havoc framework deployed for espionage operations
  • Vulnerability patched with new TrueConf version 8.5.3

Southeast Asian governments were recently targeted by a highly sophisticated supply chain attack as part of a wider cyber-espionage campaign, which experts believe is the work of the Chinese government.

Security researchers Check Point detailed their findings on Operation TrueChaos, a campaign revolving around a zero-day vulnerability in TrueConf, a video conferencing and collaboration platform which runs either in the cloud or on a company’s own servers.


https://cdn.mos.cms.futurecdn.net/UjSNcAZ5SebctebKAMQNVF-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img