Russian Foreign Intelligence Service (SVR) Cyber Actors Use JetBrains TeamCity CVE in Global Targeting
ID: 0c2c9b56-d6a2-5e8e-aaee-21e31ede4875
STIX ID: report--0c2c9b56-d6a2-5e8e-aaee-21e31ede4875
Feed Name: CERT Polska
**Executive Summary:** US and allied agencies report that Russian SVR (APT29/CozyBear) actors have been exploiting CVE-2023-42793 in JetBrains TeamCity at scale since September 2023, targeting build servers to access source code, signing certificates, and software build pipelines. The actors have escalated privileges, moved laterally, deployed backdoors, and maintained persistent access, creating significant software supply-chain risk; agencies disrupted the campaign, published IOCs, and advise affected organizations to assume compromise and initiate threat hunting and incident response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
