π¨ ACTIVE EXPLOITATION
- CISA Flags Exploited TrueConf Server Flaws Used in Head Mare Attacks
CVE-2026-72529CVE-2026-72530
Head Mare is exploiting unpatched TrueConf servers to deploy PhantomCore and PhantomGraph backdoors.- Organizations using TrueConf Server are affected, including external participants connecting to compromised servers.
- TrueConf Server versions 5.3.X before 5.3.9, 5.4.X before 5.4.9, 5.5.X before 5.5.5, and earlier are vulnerable.
- CVE-2026-72529 enables unauthenticated arbitrary script execution via TCP port 4307.
- CVE-2026-72530 enables code injection and arbitrary host-code execution through a crafted script.
- Attackers install a web shell, access the server database, and replace client installers with PhantomCore- or PhantomGraph-infected packages.
π Source: securelist.com Β· π Coverage: securitymea.com Β· π via CISA KEV (+1)
π₯ BREACHES & INCIDENTS
- TeamPCP LiteLLM attack exposes credentials from nearly 2,500 organizations
A LiteLLM supply-chain attack exposed credentials from nearly 2,500 organizations.- Organizations using LiteLLM included NVIDIA, Microsoft, Amazon Web Services, Cisco, Salesforce, Samsung, and Siemens.
- A 153GB archive contained 433,909 stolen files, including 118,829 CI/CD runner dumps linked to 2,488 corporate domains.
- TeamPCP published malicious LiteLLM versions 1.82.7 and 1.82.8 to PyPI on March 24, 2026.
- A poisoned Trivy dependency compromised LiteLLMβs build pipeline and exposed PyPI publishing tokens.
- The malware harvested environment variables, cloud credentials, Kubernetes secrets, SSH keys, and AI provider API keys during a roughly 40-minute window.
π Source: hudsonrock.com Β· π Coverage: arstechnica.com Β· π via @GossiTheDog@cyberplace.social
π΅οΈ RESEARCH & DEEP DIVES
- Researcher registers Linux device to Apple Find My People
A researcher accessed a consented Apple Find My location share from Linux.- Apple Find My users with existing accepted People location shares are affected.
- A Linux machine received live coordinates, timestamps, and accuracy data intended for Apple devices.
- The researcher used GrandSlam authentication, IDS certificates, and APNs registration to enroll Linux.
- A SubscribeAndFetch request delivered the encrypted location key, which a script decrypted.
π Source: zerotistic.blog Β· π Coverage: theregister.com Β· π via r/cybersecurity
π ADVISORIES
-
N-able Passportal bug exposes password-vault master keys
A bug in N-ableβs Passportal password manager exposed vault master keys.- N-able Passportal users, including managed service providers and small businesses, are affected.
- The vulnerability exposed password-vault master keys.
- The cloud-based design leaves Passportal risky even after the bug was patched.
π Coverage: darkreading.com Β· π via Dark Reading
-
π Source for Microsoft Defenderβs BTR.sys Driver Can Disable EDR and Antivirus Protections β malware.news
π CVEs & KEV
- Other: 21 CVEs (worst 9.8)