Top stories.
- CISA warns of actively exploited TrueConf vulnerabilities.
- Supply chain attack compromises popular Rust library.
- Data giant Alation discloses a cyberattack.
CISA warns of actively exploited TrueConf vulnerabilities.
The US Cybersecurity and Infrastructure Security Agency (CISA) has given Federal agencies until Sunday, August 23rd, to patch an actively exploited vulnerability affecting TrueConf Server video conferencing software. The flaw, tracked as CVE-2026-72529, is a missing authentication vulnerability that can "allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script." The attackers are also exploiting a second TrueConf vulnerability (CVE-2026-72530) to escape the isolated environment on the host system. Federal agencies have until September 3rd to patch this latter flaw.
SecurityWeek notes that the Ukrainian hacktivist group "Head Mare" was observed exploiting the flaws earlier this month to deploy malware against Russian and Belarusian targets.
Supply chain attack compromises popular Rust library.
Threat actors inserted malicious code into two popular Rust crates after compromising a maintainer's account, BleepingComputer reports. The attackers poisoned arrayref, which has 244 million downloads, and append-only-vec, which has 4 million downloads. According to Aikido Security, "The attacker added a malicious dependency on a package called proc-macro1, which downloads a remote payload during the build and executes it on the developer's machine. Because the dependency runs at build time, simply compiling a project that pulls in either crate is enough to trigger the infection, with no need to call any of the crate's actual functionality."
Wiz notes that the campaign shows "significant overlap" with previous supply chain attacks that have been attributed to North Korean APTs.
Data giant Alation discloses a cyberattack.
AI data giant Alation yesterday confirmed that a cyberattack was responsible for a previously disclosed incident affecting a number of its customers, TechCrunch reports. The company said in a statement, "Alation recently identified an isolated incident involving unauthorized activity in one of its systems. We are conducting a thorough investigation of what occurred and we will provide additional information as appropriate."
Alation hasn't shared details about the nature of the attack, how many customers were affected, or whether any data was stolen.