[ << ALL_FEED ]

Time to update.

More in General

Time to update ⚠️

In early December we already reported how hackers infiltrate infrastructure through unpatched vulnerabilities in the TrueConf server that administrators failed to fix, vulnerabilities that became known in late August.

Now it’s the end of January, but the situation hasn’t changed — attackers are still actively exploiting this loophole. Since the start of the year, the PT ESC IR team has investigated several incidents where a TrueConf server placed on the perimeter served as the initial attack vector.

😐 Don’t do that. It’s time to remember those New Year’s resolutions, pull yourselves together, and install updates. The vendor published a detailed security guide back in August.

Just in case, we also recommend checking your server — in case compromise has already occurred and attackers have managed to establish a foothold in the infrastructure (IoCs were published here, plus a couple of new ones from the PhantomCore group: 31.59.105.51, 31.56.227.100). MaxPatrol SIEM and PT NAD can help with detection.

And yes, if you’re going to have a call with someone via TrueConf — warn all conference participants about this 📱

#ir
@ptescalator

More from oUth0R

More from oUth0R

More in General