JetBrains disclosed that its hosted Cadence service was compromised through an unpatched TeamCity server running a vulnerability the company itself published on July 27 and warned customers was being exploited on August 7 — and stated plainly that the server should have been patched as part of its own response but was not. Attacker activity began August 8, was discovered August 23, and the server was taken offline August 24, with confirmed extraction of usernames, real names, email addresses, last-login timestamps, and last-accessed IP addresses, plus compromise of a full 2024 server backup whose credentials, configuration, artifacts, and logs must all be treated as exposed. Users are told to treat any secret stored in Cadence, contained in that backup, or used during an execution as compromised — cloud provider credentials, Git host tokens, package registry keys, SSH and deployment keys, service account credentials, signing keys — and to hunt for unexpected repository clones, unexpected commits, and changes to repository secrets, webhooks, collaborators, or permissions from August 8 onward. #DevSecOps #SupplyChainSecurity #IncidentResponse #PatchManagement #Cybersecurity https://lnkd.in/g6RihZ9w
JetBrains Cadence Service Compromised Through Unpatched TeamCity Server
More Relevant Posts
-
Grafana Labs patched a critical SSRF flaw that could turn MCP servers into proxies for accessing sensitive internal systems, highlighting new risks around #AI infrastructure. #cybersecurity #CISO #infosec
To view or add a comment, sign in
-
Discover the details of the Surfshark test server breach. Learn how a configuration error exposed internal secrets and how the VPN provider responded. #Surfshark #CyberSecurity #DataBreach #VPN #TechNews
To view or add a comment, sign in
-
CISA has published an urgent threat briefing detailing sophisticated attack vectors targeting enterprise Active Directory environments, outlining advanced lateral movement methods, Kerberoasting extensions, and stealthy persistence mechanisms currently deployed by nation-state actors to compromise hybrid cloud architectures. #CISA #Cybersecurity #ActiveDirectory #InfoSec #ThreatIntel #CloudComputing #DevSecOps #TechAlert #TechNews https://lnkd.in/d-6pmBt8
To view or add a comment, sign in
-
A compromised development environment becomes a gateway to the supply chain. How far it reaches depends on what credentials were stored there. Worms like Shai-Hulud harvested tokens from developer machines, then used them to reach private codebases, cloud storage, and further secrets. Those credentials sit with your third parties as often as they sit with you, and most of them were never scoped for what they can actually touch. We wrote previously about why inside-out monitoring surfaces - and what point-in-time assessments miss. Our new article applies that to machine identities: finding service accounts nobody ever labeled as service accounts, checking rotation and permissions on keys, and reading a repository's security settings without ever seeing the code inside. A report published recently by Truffle Security found roughly 9,000 valid AWS keys sitting in public repositories, 526 of them with root access. No attacker required for that one. The post covers how to keep this visible across your third parties, daily rather than once a year. Read it on our blog: https://lnkd.in/dZFC8c44 #Cybersecurity #TPCRM #ThirdPartyRisk #SupplyChainSecurity #InformationSecurity #AISecurity #TPRM
To view or add a comment, sign in
-
Internet exposure is sometimes a deployment accident that survives because the application itself still requires authentication. CVE-2026-85706 is a reminder that application authentication cannot compensate for every vulnerable unauthenticated endpoint. A GitLab instance intended for a small engineering group may still be reachable through a permissive security group, reverse-proxy route, or inherited firewall rule. That makes network exposure worth validating independently of the application's login controls. In practical terms, it is a good time to: - verify public DNS records and external IPs that resolve to self-managed GitLab services - inspect nftables, firewalld, cloud firewall, and reverse-proxy rules for unintended public reachability - identify administrative or legacy GitLab endpoints still reachable from untrusted networks - test exposure from an external network rather than assuming internal diagrams are current #LinuxSecurity #NetworkSecurity #CloudSecurity #SysAdmin #InfrastructureSecurity https://lnkd.in/dUSa6k2K
To view or add a comment, sign in
-
When DNS Cannot Be Trusted Overview A collection of security vulnerabilities affecting BIND 9, one of the world's most widely deployed DNS platforms, highlights the importance of protecting the infrastructure responsible for directing users and applications across networks. The identified weaknesses include DNS cache poisoning, remote crashes, resource exhaustion and DNSSEC-related issues affecting different BIND versions and configurations. Two particularly important vulnerabilities, CVE-2025-40778 and…...
To view or add a comment, sign in
-
CVE-2023-54391 (CVSS 9.3) is a missing critical step in authentication (CWE-304). Any party able to reach the Proxmox login API can obtain a valid session as any account including the host root account without supplying a password and without satisfying a second factor. Accounts that do not have two-factor authentication configured are the ones at risk, which on a default installation includes the root account itself. A Proxmox root session is not access to a single application. It confers control of every virtual machine on the host, their disks and backups, the storage configuration, and, in a clustered deployment, every other node. Observed attacker intent is overwhelmingly infrastructure takeover, with a smaller proportion associated with ransomware. The significant point for asset owners is the timeline: the underlying defect was silently corrected by the vendor in July 2023 as part of routine maintenance, but only received a CVE identifier on 1 September 2026. Organisations running affected builds have therefore been exposed for three years without any advisory to prompt action. Exploitation attempts were observed within days of publication, with 1,210 matching attempts recorded from 133 unique source addresses over a three-day window. The vulnerability is not currently listed in the CISA KEV catalog but is listed in the VulnCheck KEV catalogue. 𝗔𝗳𝗳𝗲𝗰𝘁𝗲𝗱 • Proxmox VE 7.0 through 7.4 and the initial 8.0 release • Specifically, libpve-access-control versions 7.0-7 through 8.0.3 • Fixed in libpve-access-control 8.0.4 (July 2023) • Proxmox VE 7.x reached end of life in July 2024 and never received the fix 𝗥𝗲𝗰𝗼𝗺𝗺𝗲𝗻𝗱𝗲𝗱 𝗮𝗰𝘁𝗶𝗼𝗻𝘀 • Verify the installed package version on every Proxmox host using dpkg -l libpve-access-control. Treat any version below 8.0.4 as vulnerable. • Upgrade to a supported Proxmox VE 8.x release with all current updates applied. Version 7.x cannot be patched in place and requires migration. • Remove the management interface (TCP port 8006) from direct internet exposure and place it behind a VPN or access-controlled gateway. • Note that network-edge restrictions do not protect a host reachable from a compromised workstation on the management VLAN. • Where a host has been internet-reachable, do not assume patching closes the matter. Audit user accounts, API tokens, recently created or modified virtual machines, and storage configuration changes for unauthorised activity. • Enforce two-factor authentication on all accounts, including root, as part of the wider hardening posture. • Where compromise is suspected, isolate the host, preserve logs and forensic images, rotate all credentials and API tokens, and report the incident to this Centre. #ThreatIntelligence #CyberSecurity #Proxmox #Virtualisation #CVE #PatchManagement #NCSOC
To view or add a comment, sign in
-
-
🚨 Alert: A critical bypass flaw in Uptime Kuma (CVE-2026-33130) allows attackers to perform Server-Side Template Injections (SSTI) and read arbitrary sensitive files like /etc/passwd from your host server! An incomplete patch for a previous bug left unquoted file paths unchecked. If you are running Uptime Kuma v1.23.0 - v2.2.0, upgrade to v2.2.1 immediately to protect your monitoring stack! 🔒💻 Ensure your network is thoroughly audited by scanning with Helium Security : https://lnkd.in/gvkvvjQX Read the full article below: https://lnkd.in/gTGSXNGr #Cybersecurity #CVE202633130 #UptimeKuma #HeliumSecurity #VulnerabilityManagement
To view or add a comment, sign in
-
CVE-2026-94127 is a critical F5 BIG-IP APM zero-day actively exploited in the wild, enabling unauthenticated remote code execution through a heap-based buffer overflow in vulnerable OAuth Authorization Server configurations. Because exploitation occurs through the data plane, restricting the BIG-IP management interface alone does not remove the attack surface, making patching and review of affected virtual servers a priority. Read the full article: https://lnkd.in/dCbwbdRX #Cybersecurity #CVE #Security
To view or add a comment, sign in
-
🚨 Exciting times in the cybersecurity realm! F5 has just disclosed a critical vulnerability, CVE-2026-94127, in their BIG-IP Access Policy Manager (APM). This flaw allows attackers to execute code without even needing to log in. Talk about a wake-up call! This isn’t just another vulnerability; it's a clear reminder of the importance of robust authorization servers in our tech landscape. With APM serving as an OAuth authorization server, issuing access tokens to applications, the implications are massive. Reflecting on history, we’ve seen how vulnerabilities can catalyze industry-wide shifts. Remember the SolarWinds breach? It ushered in new standards for supply chain security. As we navigate this latest concern, we can expect: - Increased scrutiny on OAuth implementations across the board. - A surge in demand for rapid patch management solutions. - Enhanced focus on security in the cloud as organizations ramp up their defenses. The future? I predict a greater emphasis on proactive measures and vulnerability assessments. It’s about time we shift from reactive to strategic security practices. Kudos to F5 for their swift advisory and hotfixes! Let’s stay vigilant and keep the conversation going. How are you preparing for vulnerabilities like these in your systems? #Cybersecurity #VulnerabilityManagement #F5BIGIP #ainews #automatorsolutions #CyberSecurityAINews ----- Original Publish Date: 2026-09-23 01:39
To view or add a comment, sign in