CyberSecurity News
TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
AI summary
A threat actor known as Head Mare is exploiting security flaws in unpatched TrueConf servers to target Russian companies. The targeted sectors include instrumentation, electronics, transport, energy, IT, and software development. The attacks were detected by Russian cybersecurity vendor Kaspersky in July 2026. The threat actor is using a vulnerability chain to carry out the attacks, which involve replacing client installers with PhantomCore.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

