LIVE · cybersecurity feed
Live wire
OpenAI Announced $1B in Defensive Tools for Water UtilitiesAttackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS CredentialsCVE-2026-59346 · Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host CodeCVE-2026-32475 · Elementor Pro WordPress Plugin Vulnerability Exploited to Hack SitesBroadcom Patches Critical VMware Workstation and Fusion VM-Escape VulnerabilitiesHackers Leak Millions of Airport Passenger Records After Ransom RefusalUsing a VM to Contain an AI AgentCVE-2026-73749 · HPE Patches Critical RCE Vulnerabilities in AOS-CXCVE-2026-14894 · Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE FlawsCisco searched for IOS XR bugs and found so many it rolled them into an update release
vulnerabilitycritical

Australia Warns of Active Exploitation of Critical TeamCity Server Flaw

Australian officials are urging TeamCity customers to patch an actively exploited critical flaw, which follows a similar warning from the US government

zeroday.news ·

The Australian Cyber Security Centre (ACSC) has issued a warning regarding the active exploitation of a critical vulnerability, CVE-2026-63077, affecting TeamCity On-Premises servers. This flaw allows unauthenticated attackers with HTTP(S) access to a TeamCity server to bypass authentication and execute arbitrary operating system commands. All versions of TeamCity On-Premises are impacted.

While the ACSC has not identified specific industries or sectors being targeted, all Australian organizations using TeamCity On-Premises are considered at risk. The agency has urged customers to promptly review their networks for vulnerable versions, apply necessary patches, and evaluate whether their TeamCity interface needs to be exposed to the internet.

TeamCity, developed by JetBrains, is a widely used Continuous Integration and Continuous Deployment (CI/CD) server that automates software build, test, and deployment processes.

JetBrains initially disclosed CVE-2026-63077, which carries a critical CVSS score of 9.8, in July 2026, at which point patches were made available. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog on August 5, citing evidence of active exploitation. CISA highlighted that such vulnerabilities are frequently targeted by malicious actors and pose significant risks to federal systems.

Two days later, JetBrains released a follow-up advisory confirming reports of both active and attempted exploitation against unpatched TeamCity servers. The company advised customers who have not yet updated to TeamCity 2025.11.7 or 2026.1.3, or installed the security patch plugin, to do so immediately.

This is not the first time TeamCity On-Premises software has been a target for attackers. In 2024, two other vulnerabilities affecting the software were reportedly exploited extensively, with one allowing for complete compromise by a remote unauthenticated attacker. Additionally, a critical vulnerability discovered in 2023 was found to have been exploited by state-sponsored actors from Russia and North Korea.

vulnerabilitypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

CVE-2026-81578

PaperCut Flaws Exploited in Attacks on U.S. and European Schools

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

breachcritical

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

CVE-2026-59346critical

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

CVE-2026-32475critical

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

patch

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]