logo

JetBrains TeamCity under attack by ransomware thugs after disclosure mess

ID: 0c035f5f-7c68-5a07-ba8c-0ab699a8a1e6

STIX ID: report--0c035f5f-7c68-5a07-ba8c-0ab699a8a1e6

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-03-07

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Security researchers report active mass exploitation of JetBrains TeamCity vulnerabilities (CVE-2024-27198 and a related bug) leading to compromised CI/CD servers, creation of hundreds of attacker accounts (noted by eight-character random usernames), and deployment of a suspected modified Jasmin ransomware variant; ~1,182 exposed vulnerable TeamCity instances remain reachable on the internet, and operators are urged to apply patches immediately while the disclosure handling between Rapid7 and JetBrains has caused community debate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.