bleeping-computer · Crawled Sep 24, 2026

CISA: Ransomware gangs now exploiting critical TeamCity flaw

1 Actors
Read original article ↗

AI Summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that ransomware gangs are actively exploiting a critical authentication bypass vulnerability in JetBrains TeamCity, tracked as CVE-2026-63077. This flaw allows unauthenticated attackers to execute arbitrary operating system commands via the TeamCity agent polling protocol, potentially compromising CI/CD pipelines, stealing credentials, and modifying server state. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and mandated federal agencies to remediate within three days. Although patching is available, hundreds of internet-exposed TeamCity servers remain unpatched, making them attractive targets for ransomware and state-sponsored actors.

AI-extracted · verify before operational use

Extracted Entities 1 found

MITRE ATT&CK TTPs 35 techniques

T1003 OS Credential Dumping · Credential Access T1021.001 Remote Desktop Protocol · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1036 Masquerading · Defense Evasion T1036.005 Match Legitimate Name or Location · Defense Evasion T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1055.001 Dynamic-link Library Injection · Defense Evasion T1056.001 Keylogging · Collection T1056.002 GUI Input Capture · Collection T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1070.004 File Deletion · Defense Evasion T1071.001 Web Protocols · Command And Control T1071.004 DNS · Command And Control T1078 Valid Accounts · Defense Evasion T1090 Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1110 Brute Force · Credential Access T1133 External Remote Services · Persistence T1136.001 Local Account · Persistence T1185 Browser Session Hijacking · Collection T1204.002 Malicious File · Execution T1480 Execution Guardrails · Defense Evasion T1495 Firmware Corruption · Impact T1556 Modify Authentication Process · Credential Access T1558 Steal or Forge Kerberos Tickets · Credential Access T1566 Phishing · Initial Access T1566.001 Spearphishing Attachment · Initial Access T1570 Lateral Tool Transfer · Lateral Movement T1586 Compromise Accounts · Resource Development T1588 Obtain Capabilities · Resource Development T1595.002 Vulnerability Scanning · Reconnaissance T1659 Content Injection · Initial Access T1684.001 T1684.001