JetBrains TeamCity Mass Exploitation Underway, Rogue Accounts Thrive
ID: ad82f9f8-a993-5bb2-b613-3a8446b99092
STIX ID: report--ad82f9f8-a993-5bb2-b613-3a8446b99092
Feed Name: Dark Reading
The report details active exploitation of two JetBrains TeamCity authentication-bypass vulnerabilities (notably CVE-2024-27198 with CVSS 9.8) that enable attackers to create administrative accounts, achieve remote code execution, deploy malicious plugins or payloads, and in observed cases distribute a modified Jasmin ransomware; security groups (Rapid7, CrowdStrike, ShadowServer, LeakIX) reported thousands of exposed or compromised TeamCity instances and urged immediate patching to prevent supply-chain and large-scale propagation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
