Visualização normal

Antes de ontemStream principal
  • ✇Cybersecurity News
  • JetBrains Cadence Server Compromised Do Son
    An unpatched JetBrains Cadence server exposed cloud infrastructure, AWS credentials, and critical developer secrets. Discover the details of this severe breach. Related Posts: Meta Settles Child Privacy Lawsuit Rapidly Mercor Data Breach Targets AI Supply Chain Exposed Git Repositories Leak Critical Cloud Secrets The post JetBrains Cadence Server Compromised appeared first on Daily CyberSecurity.
     

JetBrains Cadence Server Compromised

Por:Do Son
30 de Agosto de 2026, 23:50

An unpatched JetBrains Cadence server exposed cloud infrastructure, AWS credentials, and critical developer secrets. Discover the details of this severe breach.

Related Posts:

The post JetBrains Cadence Server Compromised appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • Australia Warns of Hackers Exploiting TeamCity Flaw, PoC Public Do Son
    TeamCity CVE-2026-63077 enables unauthenticated remote code execution. Exploited in the wild with a public PoC. Patch your servers now. Related Posts: CVE-2026-14669: PoC Code Enables RCE in PostgreSQL TP-Link Fixes Three High-Severity TL-MR6400 Router Flaws CVE-2026-74480 (CVSS 9.8): Linux Kernel Privilege Escalation PoC Public The post Australia Warns of Hackers Exploiting TeamCity Flaw, PoC Public appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-75045: Unauthenticated Attacker Could Download YouTrack Database Backups Do Son
    JetBrains patched CVE-2026-75045, letting an unauthenticated attacker download YouTrack database backups. Eight flaws fixed. Update now. Related Posts: CVE-2026-71290: Apache HttpClient Flaw Lets Attackers Intercept and Modify Traffic (CVSS 9.1) PoC Discloses for CVE-2026-64849: watchTowr Sees Attacks on MLflow SSRF GeoServer Unauthenticated SQL Injection (CVSS 9.8) Exploited in the Wild, PoC Public The post CVE-2026-75045: Unauthenticated Attacker Could Download YouTrack Database Backups app
     
  • ✇Cybersecurity News
  • PoC Releases for CVE-2026-63077: TeamCity RCE Exploited in the Wild Do Son
    CVE-2026-63077, an unauthenticated RCE in JetBrains TeamCity, is exploited in the wild. PoC exploit code and full details are now public. Related Posts: CVE-2026-27912: PoC Released for SYSTEM Privilege Flaw CVE-2026-58231 (CVSS 10.0) and Code Injection RCE Flaws Top SAP August 2026 Patch Day Windows PnP Attack Chain Turns a USB Plug Into SYSTEM: Details and PoC Now Public The post PoC Releases for CVE-2026-63077: TeamCity RCE Exploited in the Wild appeared first on Daily CyberSecurity.
     
  • ✇Security Affairs
  • JetBrains Patches Critical TeamCity Flaw Allowing Server Takeover Pierluigi Paganini
    JetBrains patched a critical TeamCity flaw (CVE-2026-63077) enabling unauthenticated code execution on affected on-premise servers. JetBrains has released security updates for TeamCity On-Premises after discovering a critical vulnerability, tracked as CVE-2026-63077 (CVSS score of 9.8). The flaw could allow unauthenticated attackers to execute arbitrary commands on affected servers. All on-premise versions are impacted, while TeamCity Cloud instances have already been patched. Users are advi
     

JetBrains Patches Critical TeamCity Flaw Allowing Server Takeover

28 de Julho de 2026, 08:17

JetBrains patched a critical TeamCity flaw (CVE-2026-63077) enabling unauthenticated code execution on affected on-premise servers.

JetBrains has released security updates for TeamCity On-Premises after discovering a critical vulnerability, tracked as CVE-2026-63077 (CVSS score of 9.8). The flaw could allow unauthenticated attackers to execute arbitrary commands on affected servers. All on-premise versions are impacted, while TeamCity Cloud instances have already been patched. Users are advised to upgrade to versions 2025.11.7 or 2026.1.3.

“A critical security vulnerability has been identified in TeamCity On-Premises and assigned the Common Vulnerabilities and Exposures (CVE) identifier CVE-2026-63077.” reads the advisory. “If exploited, this vulnerability may allow an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands.”

The TeamCity vulnerability affects servers exposed via HTTP(S) and can be exploited without authentication through the agent polling protocol. An attacker could bypass authentication and execute arbitrary OS commands with TeamCity server privileges, potentially accessing sensitive data, credentials, configurations, altering server settings, and compromising CI/CD pipelines. JetBrains recommends restricting network access, applying least-privilege configurations, and running TeamCity on dedicated hosts separated from build agents. No active exploitation has been observed at disclosure time.

The company has also released a security patch plugin for organizations unable to immediately upgrade TeamCity to versions 2025.11.7 or 2026.1.3. The plugin fixes only CVE-2026-63077 and can be installed on TeamCity 2017.1 and later. For newer versions, security patches can be managed directly from the administration console.

“The security patch plugin will address only the vulnerability described above (CVE-2026-63077).” continues the advisory.”We always recommend upgrading your server to the latest version to benefit from many other security updates.”

JetBrains recommends protecting internet-facing TeamCity servers by requiring VPN access or adding extra security controls. Exposing login pages or REST APIs can provide attackers with potential entry points to exploit newly disclosed vulnerabilities.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CVE-2026-63077)

15 Malicious JetBrains Plugins Caught Stealing DeepSeek, OpenAI API Keys

Hackers are using 15 malicious JetBrains plugins posing as AI coding assistants to steal DeepSeek, OpenAI, and other developer API keys.
❌
❌