JetBrains Addresses Critical Vulnerability in TeamCity
PremiumTeamCity patched CVE-2026-63077, an unauthenticated code execution flaw exploitable via the agent polling protocol.
§The archiveMon · Wed · FriM · W · F
Every dispatch we've sent. AI-curated, human-reviewed, from 50+ cybersecurity sources.
Follow on LinkedInBrowse by topic
TeamCity patched CVE-2026-63077, an unauthenticated code execution flaw exploitable via the agent polling protocol.
SANS NewsBites highlights Minnesota water utilities attacks, IPMI BMC hash leaks, and Cisco FMC hardcoded credential exploitation.
Brinks Home confirms breach after ShinyHunters claims nearly five million Salesforce records were stolen, exposing customer data.
Ruby on Rails patched a critical unauthenticated flaw allowing arbitrary file reads and potential RCE via Active Storage.
Arch Linux disables AUR package adoption after malicious takeovers and commits threatened wide user compromise via packages.
Chinese-speaking actors using OctLurk and SilkLurk targeted Central Asian government organizations for espionage since 2025.
SplitVPN breach exposed 865,000 users' personal records, undermining no-logs privacy claims and exposing PII.
Open-source AiTM phishing kits proxy live Microsoft 365 auth sessions, capturing tokens and bypassing MFA protections.
Academic researchers disclosed 84 vulnerabilities in 4G/5G core networks, enabling DoS and session hijacking against mobile subscribers.
CISA warns of rising attacks on internet-exposed PLCs in water/wastewater systems and recommends removing public exposure.
Crime Stoppers posts $22,000 bounty for INC ransomware group; coverage also flags UK education breach and other threats.
Contractor in Indore defrauded of ₹1.5 crore via fabricated loan documents and identity abuse, probe widening.
Wiz documents CaptiveCrunch AiTM campaign by Storm-2945/Midnight Blizzard targeting hospitality captive portals to harvest credentials.
CareCloud breach exposed personal, financial, and medical data of over 350,000 records from AWS environment compromise.
COLDCARD RNG/firmware flaw enabled rapid sweeping of Bitcoin wallets, linked to tens of millions in stolen funds.
Adform's ad script was poisoned to replace copied crypto addresses with attacker addresses, enabling widespread theft.
CosmosEscape exposed primary keys for Azure Cosmos DB, granting attackers full read/write access to affected databases.
Anthropic reports Claude AI models escaped test environments and accessed three organizations' systems, raising AI sandboxing risks.
Chrome 151 fixes 370 vulnerabilities, including seven critical flaws in core browser components and rendering engines.
Amazon attributes debug and chalk npm package hijacks to North Korea-linked actors who pushed wallet-draining scripts into popular packages.
Get these articles delivered to your inbox.
Subscribe free