LIVE · cybersecurity feed
Live wire
Australia Warns of Active Exploitation of Critical TeamCity Server FlawCVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attackHackers target WordPress sites in miniOrange auth bypass attacksFake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)Fake Microsoft security scans trick victims into uninstalling their antivirusCVE-2026-19478 · ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreThe Vulnerability Gap: Why Discovery Is Outrunning RepairCISA’s logging guidance works beyond government
vulnerabilitycritical

Australia Warns of Active Exploitation of Critical TeamCity Server Flaw

Australian officials are urging TeamCity customers to patch an actively exploited critical flaw, which follows a similar warning from the US government

zeroday.news ·

The Australian Cyber Security Centre (ACSC) has issued a warning regarding the active exploitation of a critical vulnerability, CVE-2026-63077, affecting TeamCity On-Premises servers. This flaw allows unauthenticated attackers with HTTP(S) access to a TeamCity server to bypass authentication and execute arbitrary operating system commands. All versions of TeamCity On-Premises are impacted.

While the ACSC has not identified specific industries or sectors being targeted, all Australian organizations using TeamCity On-Premises are considered at risk. The agency has urged customers to promptly review their networks for vulnerable versions, apply necessary patches, and evaluate whether their TeamCity interface needs to be exposed to the internet.

TeamCity, developed by JetBrains, is a widely used Continuous Integration and Continuous Deployment (CI/CD) server that automates software build, test, and deployment processes.

JetBrains initially disclosed CVE-2026-63077, which carries a critical CVSS score of 9.8, in July 2026, at which point patches were made available. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog on August 5, citing evidence of active exploitation. CISA highlighted that such vulnerabilities are frequently targeted by malicious actors and pose significant risks to federal systems.

Two days later, JetBrains released a follow-up advisory confirming reports of both active and attempted exploitation against unpatched TeamCity servers. The company advised customers who have not yet updated to TeamCity 2025.11.7 or 2026.1.3, or installed the security patch plugin, to do so immediately.

This is not the first time TeamCity On-Premises software has been a target for attackers. In 2024, two other vulnerabilities affecting the software were reportedly exploited extensively, with one allowing for complete compromise by a remote unauthenticated attacker. Additionally, a critical vulnerability discovered in 2023 was found to have been exploited by state-sponsored actors from Russia and North Korea.

vulnerabilitypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

Disclosed in January and honeypots buzzed soon after, CISA says it’s finally time for the USG to plug the gap

CVE-2026-73570

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. About CVE-2026-73570 Zimbra Collaboration Suite (ZCS) is a communication and collaboration platform popular with organizations that need to have control over their data or can’t afford a pricy alternative service like Microsoft 365 or Google Wor

malware

First Malware Built Specifically for Car Head Units Fuels Botnet

Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices. The post First Malware Built Specifically for Car Head Units Fuels Botnet appeared first on SecurityWeek.

security

The County Prosecutors Who Became ICE Informants

Illinois prosecutors shared defendants’ personal data with federal immigration agents without criminal warrants, public disclosure, or legislative oversight.

malware

Fake Minecraft Clients Deliver WeedHack Malware Despite Infrastructure Takedown

A threat actor keeps spreading the WeedHack malware to Minecraft players despite its original infrastructure taken down in July

security

ReliaQuest Rejects Compromise Claims After ShinyHunters Incident

ReliaQuest has detailed a social engineering attack linked to ShinyHunters, denying reports that the threat actor successfully compromised its systems