CISA tells federal agencies to patch exploited TrueConf Server flaws
Source headline: CISA orders feds to patch actively exploited TrueConf Server flaws
Intelligence Summary
CISA ordered U.S. federal agencies to prioritize patching vulnerabilities in TrueConf Server. The order covers two flaws that are actively exploited in the wild. The issues affect the TrueConf Server self-hosted communications platform. This creates risk for agencies and organizations running the software. Since exploitation is ongoing, defenders should treat the update as urgent. Apply the available patches for TrueConf Server immediately.
Recommended Action
Inventory where TrueConf Server runs in your environment and treat this as an active remediation item. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.