Jetbrains News Articles

Recent news articles refferecing the vendors vulnerabilities.

JetBrains patches new TeamCity authentication bypass bugs

TeamCity servers risk being exposed to “complete compromise” if patch isn’t installed, researchers warned.

5 months ago

CVE-2024-37051: кибербандиты похищают GitHub-токены через IntelliJ IDEA

Как популярная среда разработки стала точкой входа для дальнейшей компрометации?

6 months ago

Users of JetBrains IDEs at risk of GitHub access token compromise (CVE-2024-37051) - Help Net Security

CVE-2024-37051 could expose users of JetBrains' integrated development environments (IDEs) to GitHub access token compromise.

6 months ago

Трендовые уязвимости марта: обновляйтесь и импортозамещайтесь

Хабр, привет! Я Александр Леонов, и мы с командой аналитиков Positive Technologies каждый месяц изучаем информацию о недостатках безопасности из баз, бюллетеней безопасности вендоров, социальных...

8 months ago

PravinKarthik

Read all of the posts by PravinKarthik on TheCyberThrone

9 months ago

Attackers are exploiting JetBrains TeamCity flaw to deliver a variety of malware - Help Net Security

Attackers are exploiting the JetBrains TeamCity auth bypass vulnerability (CVE-2024-27198) to deliver ransomware, cryptominers and RATs.

9 months ago

TeamCity Vulnerability Exploits Lead to Jasmin Ransomware, Other Malware Types

CVE-2024-27198 and CVE-2024-27199 are vulnerabilities within the TeamCity On-Premises platform that can allow attackers to gain administrative control over affected systems.

9 months ago

TeamCity Vulnerability Exploits Lead to Jasmin Ransomware, Other Malware Types

CVE-2024-27198 and CVE-2024-27199 are vulnerabilities within the TeamCity On-Premises platform that can allow attackers to gain administrative control over affected systems.

9 months ago

Microsoft & Midnight Blizzard, New X Calling Feature Privacy Risks, and More | PacketWatch Threat Intelligence | March 11, 2024

Lessons from Microsoft's Midnight Blizzard security update, X's new calling feature privacy risk, and recent vulnerabilities with VMware, JetBrains, and QNAP.

9 months ago

Two critical vulnerabilities, being tracked as CVE-2024-27198 & CVE-2024-27199, have been discovered and patched in JetBrains TeamCity, affecting all TeamCity On-Premises versions through 2023.11.3. we recommend applying fixes immediately. Learn More.

Two critical vulnerabilities, being tracked as CVE-2024-27198 & CVE-2024-27199, have been discovered and patched in JetBrains TeamCity, affecting all TeamCity On-Premises versions through 2023.11.3. we recommend applying fixes immediately. Learn More.

9 months ago

Recent TeamCity Vulnerability Exploited in Ransomware Attacks

Servers impacted by recently patched TeamCity vulnerability CVE-2024-27198 targeted in ransomware attacks and abused for DDoS.

9 months ago

CISA adds JetBrains TeamCity bug to its Known Exploited Vulnerabilities catalog

U.S. CISA adds a JetBrains TeamCity vulnerability to its Known Exploited Vulnerabilities catalog................

9 months ago

Update now! JetBrains TeamCity vulnerability abused at scale | Malwarebytes

Users of JetBrains'TeamCity on-prmises server should be updating or patching their instances because of large scale active exploitation

9 months ago

CISA Warns of Actively Exploited JetBrains TeamCity Vulnerability

CISA has added a critical JetBrains TeamCity flaw (CVE-2024-27198, CVSS 9.8) to its KEV catalog due to active exploitation.

9 months ago

Critical TeamCity Vulnerability Exploitation Started Immediately After Disclosure

Critical TeamCity authentication bypass vulnerability CVE-2024-27198 exploited in the wild after details were disclosed.

10 months ago

アメックスの一部顧客データが漏洩の可能性、原因はサードパーティの侵害 | Codebook|Security News

アメリカン・エキスプレスは顧客に対し、ある加盟店処理業者で発生したデータ侵害によって一部顧客のカード情報が不正なアクセスを受けた可能性があると警告した。流出した可能性のあるデータには、現在または過去に発行されたカードのアカウント番号や顧客名、有効期限といった情報が含まれるという。

10 months ago

Critical TeamCity flaw now widely exploited to create admin accounts

Hackers have started to exploit the critical-severity authentication bypass vulnerability (CVE-2024-27198) in TeamCity On-Premises, which JetBrains addressed in an update on Monday.

10 months ago

TeamCity auth bypass bug exploited to mass-generate admin accounts

Hackers have started to exploit the critical-severity authentication bypass vulnerability (CVE-2024-27198) in TeamCity On-Premises, which JetBrains addressed in an update on Monday.

10 months ago

Critical JetBrains TeamCity vulnerabilities under attack | TechTarget

Multiple companies have confirmed exploitation activity against two authentication bypass vulnerabilities that affect JetBrains TeamCity servers.

10 months ago

JetBrains Fixes TeamCity Authentication Bypass Flaws

The flaws, which exist in all TeamCity on-premises versions through 2023.11.3, have been fixed in version 2023.11.4.

10 months ago

Rapid7 flames JetBrains over vulnerability disclosure

Updated Security shop Rapid7 is criticizing JetBrains for flouting its policy against silent patching regarding fixes for two fresh vulnerabilities in the TeamCity CI/CD server. Rapid7 says it reported the...

10 months ago

Exploit available for new critical TeamCity auth bypass bug, patch now

A critical vulnerability (CVE-2024-27198) in the TeamCity On-Premises CI/CD solution from JetBrains can let a remote unauthenticated attacker take control of the server with administrative permissions.

10 months ago

Critical vulnerabilities in TeamCity JetBrains fixed, release of technical details imminent, patch quickly! (CVE-2024-27198, CVE-2024-27199) - Help Net Security

JetBrains fixes critical security vulnerabilities (CVE-2024-27198, CVE-2024-27199) in TeamCity On-Premises and advises immediate patching.

10 months ago

Article: CVE-2024-23917 TeamCity On-Premises Vulnerability - WNEsecurity

CVE-2024-23917 TeamCity On-Premises Vulnerability may enable an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication...

10 months ago

CVE-2024-23917: Critical Vulnerability Affecting On-Premises Servers Of TeamCity – CyberIQs

On 5 February 2023, JetBrains published a blog describing a critical vulnerability (CVE-2024-23917) affecting the On-Premises Servers of TeamCity. An

10 months ago

CVE-2024-23917 | Arctic Wolf

On February 5, 2023, JetBrains published a blog describing a critical vulnerability (CVE-2024-23917) affecting the On-Premises Servers of TeamCity. Find Arctic Wolf's recommendations.

10 months ago

JetBrains Patches Critical Authentication Bypass in TeamCity

JetBrains issued a warning about a critical authentication bypass vulnerability in TeamCity, a widely-used build management server, which could be exploited remotely for arbitrary code execution. Tracked as CVE-2024-23917 with a CVSS score of 9.8, the flaw affects all TeamCity On-Premises versions f...

10 months ago

Patch Now: Critical TeamCity Bug Allows for Server Takeovers

Cyberattackers can exploit a vulnerability in JetBrain's continuous integration and delivery (CI/CD) server (APT target) to gain administrative control.

10 months ago

Patched Critical Flaw Exposed JetBrains TeamCity Servers

Tracked as CVE-2024-23917, the flaw carries a CVSS rating of 9.8

10 months ago

Experts warn of critical JetBrains TeamCity On-Premises bug

A new vulnerability in JetBrains TeamCity On-Premises can be exploited by threat actors to take over vulnerable instances.

10 months ago

JetBrains issues urgent patches for critical TeamCity vuln

JetBrains is encouraging all users of TeamCity (on-prem) to upgrade to the latest version following the disclosure of a critical vulnerability in the CI/CD tool. Tracked as CVE-2024-23917, the vulnerability...

10 months ago

TeamCity Authentication Bypass Flaw Let Attackers Gain Admin Control

A critical security vulnerability was detected in TeamCity Authentication On-Premises tagged as CVE-2024-23917 with a CVSS score of 9.8.

10 months ago

On-premises JetBrains TeamCity servers vulnerable to auth bypass (CVE-2024-23917) - Help Net Security

JetBrains has patched a critical auth bypass vulnerability (CVE-2024-23917) affecting TeamCity On-Premises servers.

10 months ago

Critical JetBrains TeamCity On-Premises Flaw Exposes Servers to Takeover - Patch Now

Critical Flaw in JetBrains TeamCity On-Premises (CVE-2024-23917) Allows Attackers to Take Over Servers

10 months ago

JetBrains Patches Critical Authentication Bypass in TeamCity

JetBrains releases patches for a critical-severity TeamCity authentication bypass leading to remote code execution.

10 months ago

JetBrains warns of new TeamCity auth bypass vulnerability

JetBrains urged customers today to patch their TeamCity On-Premises servers against a critical authentication bypass vulnerability that can let attackers take over vulnerable instances with admin privileges.

10 months ago

Critical Security Issue Affecting TeamCity On-Premises (CVE-2024-23917) – Update to 2023.11.3 Now | The TeamCity Blog

Summary A critical security vulnerability was identified in TeamCity On-Premises (initially discovered and reported by an external security researcher on January 19, 2024). This critical securi

10 months ago

'Midnight Blizzard' Breached HPE Email Months Before Microsoft Hack

The Russian APT behind the SolarWinds attacks exfiltrated data from HPE email accounts last May.

11 months ago

CISA mette in guardia da CozyBear che sfrutta CVE-2023-42793 -

CISA e partner internazionali rilasciano un avviso su Cozy Bear che sfrutta la vulnerabilità CVE-2023-42793 in JetBrains TeamCity.

1 year ago