Posts tagged with “ransomware”

TeamCity flaw CVE-2026-63077 now used by ransomware gangs

A critical authentication bypass in JetBrains TeamCity is now being abused by ransomware operators, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The agency flagged the change on Wednesday, two months after JetBrains released a fix.

The vulnerability, tracked as CVE-2026-63077, affects TeamCity On-Premises. JetBrains patched it on July 25 in versions 2025.11.7 and 2026.1.3. Attackers who can reach a server over HTTP(S) can use it to run arbitrary operating system commands.

How the flaw works

TeamCity is a Continuous Integration and Continuous Deployment (CI/CD) platform. Developers and DevOps teams use it to automate how software code is built, tested and deployed. That role makes a compromised server valuable to attackers.

Read More