Close Menu
NCIJ Network NCIJ Network
    What's Hot

    What are Cook County judicial retention elections?

    September 24, 2026

    Hundreds of immigrants, refugees await English education as Literacy Green Bay weathers federal cuts

    September 24, 2026

    Poland says fire at Starlink station is sabotage as Denmark warns of rising Russian threat

    September 24, 2026
    Facebook X (Twitter) Instagram
    Trending
    • What are Cook County judicial retention elections?
    • Hundreds of immigrants, refugees await English education as Literacy Green Bay weathers federal cuts
    • Poland says fire at Starlink station is sabotage as Denmark warns of rising Russian threat
    • EU launches diplomatic offensive to stop Trump’s diesel export ban – POLITICO
    • The Inquiry – How did Italian politics become stable?
    • Bose Ultra Open Earbuds Are $100 Off Right Now
    • CISA: Ransomware gangs now exploiting critical TeamCity flaw
    • Cosmos restarted to seize $2.2 million in stolen ATOM, but 169,000 tokens still escaped
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 24
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    CISA: Ransomware gangs now exploiting critical TeamCity flaw

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 24, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    ​The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July.

    JetBrains patched the security flaw (tracked as CVE-2026-63077) on July 25 in TeamCity On-Premises versions 2025.11.7 and 2026.1.3, saying it is a critical authentication bypass vulnerability that lets attackers with HTTP(S) access execute arbitrary operating system commands.

    “An unauthenticated attacker could exploit the vulnerability via the TeamCity agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process,” it said.

    “Depending on the privileges granted to the TeamCity server process, a successful attack could expose TeamCity data, configurations, and stored credentials, modify server state, and potentially compromise the integrity of build artifacts and downstream CI/CD pipelines.”

    Almost two weeks later, on August 5, CISA added CVE-2026-63077 to its catalog of actively exploited vulnerabilities and ordered U.S. federal agencies to secure their networks against ongoing attacks within three days.

    JetBrains confirmed that the flaw was exploited in the wild on August 7, shared indicators of compromise, and urged customers who couldn’t immediately patch their servers to limit access to trusted networks.

    Now exploited in ransomware attacks

    While CISA has not yet shared information about attacks targeting CVE-2026-63077, it updated its Known Exploited Vulnerabilities Catalog (KEV) again on Wednesday, flagging the vulnerability as being abused by ransomware gangs.

    In total, since October 2023, the cybersecurity agency has tagged four TeamCity security issues as exploited in the wild, all of which have also been abused in ransomware attacks.

    Security threat watchdog Shadowserver is now tracking just over 160 TeamCity servers unpatched against the CVE-2026-63077 flaw, down from an initial 700 Internet-exposed servers vulnerable to attacks spotted right after the vulnerability was patched.

    Unpatched TeamCity servers exposed online
    Unpatched TeamCity servers exposed online (Shadowserver)

    ​Because state-backed hacking groups and ransomware gangs have often leveraged TeamCity vulnerabilities in attacks, IT administrators are advised to patch Internet-exposed servers immediately.

    For instance, in October 2024, U.S. and U.K. cyber agencies warned that APT29 hackers linked to Russia’s Foreign Intelligence Service (SVR) were targeting vulnerable JetBrains TeamCity and Zimbra servers “at a mass scale.” 

    TeamCity is a Continuous Integration and Continuous Deployment (CI/CD) platform used by software developers and DevOps teams to automate building, testing, and deploying software code.

    JetBrains says more than 30,000 DevOps teams use TeamCity at many high-profile companies, including Citibank, Amazon Games, Tesla, and Samsung.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    CISA critical exploiting Flaw gangs ransomware TeamCity
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators

    OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files

    58 hardware vulnerabilities: A guide to the threats

    Critical WordPress Vulnerability Exploited Immediately After Disclosure

    Hackers start exploiting critical WordPress flaw for code execution

    Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    What are Cook County judicial retention elections?

    September 24, 2026

    Hundreds of immigrants, refugees await English education as Literacy Green Bay weathers federal cuts

    September 24, 2026

    Poland says fire at Starlink station is sabotage as Denmark warns of rising Russian threat

    September 24, 2026

    EU launches diplomatic offensive to stop Trump’s diesel export ban – POLITICO

    September 24, 2026
    Latest Posts

    Ransom Cartel ransomware creator sentenced to 16 years in prison

    August 5, 2026

    Uber CEO brushes off reports of a Waymo break-up

    August 5, 2026

    Fauci Faces Contempt Vote. Here Are the Legal Issues Involved.

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    What are Cook County judicial retention elections?

    September 24, 2026

    Hundreds of immigrants, refugees await English education as Literacy Green Bay weathers federal cuts

    September 24, 2026

    Poland says fire at Starlink station is sabotage as Denmark warns of rising Russian threat

    September 24, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.