- Sources: primary, discussion
- Summary: The Head Mare group compromised unpatched on-premise TrueConf conferencing servers and replaced the client installers those servers distribute with backdoored builds. The trojanized clients are unsigned. BleepingComputer reports the affected versions as TrueConf Server 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and older releases, fixed in 5.3.9, 5.4.9, and 5.5.5 published 2026-06-18.
- Why it matters: A compromised on-premise conferencing server hands a backdoored client to everyone who connects to it, including partner organizations that never operated TrueConf themselves.
send feedback on this story