Check Point Research uncovered a targeted espionage campaign dubbed 'Operation TrueChaos' against Southeast Asian government entities. Attackers exploited a zero-day vulnerability (CVE-2026-3502, CVSS 7.8) in TrueConf's client update mechanism, which lacked integrity and authenticity checks. By compromising a centrally managed

8m read timeFrom research.checkpoint.com
Post cover image
Table of contents
Key PointsIntroductionAbout TrueConfCVE-2026-3502 Root Cause AnalysisIn-The-Wild ExploitationAttributionConclusionHunting RecommendationsIndicators of Compromise

Sort: