View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

CISA Flags Exploited TrueConf Server Flaws Used in Head Mare Attacks

🚨 ACTIVE EXPLOITATION

  • CISA Flags Exploited TrueConf Server Flaws Used in Head Mare Attacks CVE-2026-72529 CVE-2026-72530
    Head Mare is exploiting unpatched TrueConf servers to deploy PhantomCore and PhantomGraph backdoors.
    • Organizations using TrueConf Server are affected, including external participants connecting to compromised servers.
    • TrueConf Server versions 5.3.X before 5.3.9, 5.4.X before 5.4.9, 5.5.X before 5.5.5, and earlier are vulnerable.
    • CVE-2026-72529 enables unauthenticated arbitrary script execution via TCP port 4307.
    • CVE-2026-72530 enables code injection and arbitrary host-code execution through a crafted script.
    • Attackers install a web shell, access the server database, and replace client installers with PhantomCore- or PhantomGraph-infected packages.
      πŸ“„ Source: securelist.com Β· πŸ“Ž Coverage: securitymea.com Β· πŸ‘ via CISA KEV (+1)

πŸ’₯ BREACHES & INCIDENTS

  • TeamPCP LiteLLM attack exposes credentials from nearly 2,500 organizations
    A LiteLLM supply-chain attack exposed credentials from nearly 2,500 organizations.
    • Organizations using LiteLLM included NVIDIA, Microsoft, Amazon Web Services, Cisco, Salesforce, Samsung, and Siemens.
    • A 153GB archive contained 433,909 stolen files, including 118,829 CI/CD runner dumps linked to 2,488 corporate domains.
    • TeamPCP published malicious LiteLLM versions 1.82.7 and 1.82.8 to PyPI on March 24, 2026.
    • A poisoned Trivy dependency compromised LiteLLM’s build pipeline and exposed PyPI publishing tokens.
    • The malware harvested environment variables, cloud credentials, Kubernetes secrets, SSH keys, and AI provider API keys during a roughly 40-minute window.
      πŸ“„ Source: hudsonrock.com Β· πŸ“Ž Coverage: arstechnica.com Β· πŸ‘ via @GossiTheDog@cyberplace.social

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • Researcher registers Linux device to Apple Find My People
    A researcher accessed a consented Apple Find My location share from Linux.
    • Apple Find My users with existing accepted People location shares are affected.
    • A Linux machine received live coordinates, timestamps, and accuracy data intended for Apple devices.
    • The researcher used GrandSlam authentication, IDS certificates, and APNs registration to enroll Linux.
    • A SubscribeAndFetch request delivered the encrypted location key, which a script decrypted.
      πŸ“„ Source: zerotistic.blog Β· πŸ“Ž Coverage: theregister.com Β· πŸ‘ via r/cybersecurity

πŸ“‹ ADVISORIES

  • N-able Passportal bug exposes password-vault master keys
    A bug in N-able’s Passportal password manager exposed vault master keys.

    • N-able Passportal users, including managed service providers and small businesses, are affected.
    • The vulnerability exposed password-vault master keys.
    • The cloud-based design leaves Passportal risky even after the bug was patched.
      πŸ“Ž Coverage: darkreading.com Β· πŸ‘ via Dark Reading
  • πŸ“„ Source for Microsoft Defender’s BTR.sys Driver Can Disable EDR and Antivirus Protections β€” malware.news

πŸ”“ CVEs & KEV

  • Other: 21 CVEs (worst 9.8)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check