logo

JetBrains TeamCity Mass Exploitation Underway, Rogue Accounts Thrive

ID: ad82f9f8-a993-5bb2-b613-3a8446b99092

STIX ID: report--ad82f9f8-a993-5bb2-b613-3a8446b99092

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2024-03-07

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

The report details active exploitation of two JetBrains TeamCity authentication-bypass vulnerabilities (notably CVE-2024-27198 with CVSS 9.8) that enable attackers to create administrative accounts, achieve remote code execution, deploy malicious plugins or payloads, and in observed cases distribute a modified Jasmin ransomware; security groups (Rapid7, CrowdStrike, ShadowServer, LeakIX) reported thousands of exposed or compromised TeamCity instances and urged immediate patching to prevent supply-chain and large-scale propagation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.