logo

Russian Foreign Intelligence Service (SVR) Cyber Actors Use JetBrains TeamCity CVE in Global Targeting

ID: 0c2c9b56-d6a2-5e8e-aaee-21e31ede4875

STIX ID: report--0c2c9b56-d6a2-5e8e-aaee-21e31ede4875

Feed Name: CERT Polska

Threat Score
90/100

Date Published: 2023-12-13

Date Updated: 2026-04-19

Author: CERT Polska

...
...

**Executive Summary:** US and allied agencies report that Russian SVR (APT29/CozyBear) actors have been exploiting CVE-2023-42793 in JetBrains TeamCity at scale since September 2023, targeting build servers to access source code, signing certificates, and software build pipelines. The actors have escalated privileges, moved laterally, deployed backdoors, and maintained persistent access, creating significant software supply-chain risk; agencies disrupted the campaign, published IOCs, and advise affected organizations to assume compromise and initiate threat hunting and incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.