threat-intel TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore Russian cybersecurity vendor TrueConf has been repeatedly targeted by the threat actor known as Head Mare, who leverages zero-day vulnerabilities in their server software to deploy a backdoor (PhantomCore) and a related tool (PhantomGraph). The attacks, ongoing since at least May 2026, are aimed at Russian companies ac… The Hacker News · Aug 10, 2026 High CVE-2026-3502CHRUzero-dayaptbackdoor