“By replacing a legitimate update with a malicious update, they turned the product update flow into a malware distribution channel”: Experts discover flaw in TrueConf video conferencing tool used by governments and military


  • Sophisticated supply chain attack exploited TrueConf update process
  • Havoc framework deployed for espionage operations
  • Vulnerability fixed with the new version TrueConf 8.5.3

Southeast Asian governments have recently been the target of a highly sophisticated supply chain attack as part of a broader cyberespionage campaign, which experts believe is the work of the Chinese government.

Security researchers Check Point have detailed their findings on Operation TrueChaos, a campaign revolving around a zero-day vulnerability in TrueConf, a video conferencing and collaboration platform that runs either in the cloud or on a company’s own servers.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top