TechSignal.news
Cybersecurity

Ransomware Groups Exploit JetBrains TeamCity Flaw, CISA Adds 10 More Vulnerabilities

CISA confirmed ransomware exploitation of a critical TeamCity authentication bypass, while 10 additional vulnerabilities entered the Known Exploited catalog in seven days.

TechSignal.news AI5 min read

Ransomware groups are exploiting JetBrains TeamCity authentication bypass

CISA confirmed ransomware gangs are actively exploiting CVE-2026-63077, a critical authentication-bypass vulnerability in JetBrains TeamCity On-Premises. An attacker with HTTP(S) access can execute arbitrary operating-system commands on vulnerable servers.

JetBrains patched the issue on July 25 in TeamCity On-Premises 2025.11.7 and 2026.1.3. CISA added it to the Known Exploited Vulnerabilities catalog on August 5 with a three-day remediation deadline for federal agencies, then updated the entry on September 24 to specifically identify ransomware exploitation.

The vulnerability matters because TeamCity is a continuous-integration/continuous-delivery platform that typically has access to source code, build credentials, signing keys, deployment tokens, and production environments. A compromised TeamCity server gives attackers a direct path to software supply chains and deployment infrastructure.

Enterprises running self-hosted TeamCity should treat patching as an incident-priority task, inventory internet-accessible servers, rotate credentials reachable from build agents, and review recent build activity for unauthorized changes. The concrete ransomware attribution moves this from theoretical exposure to a confirmed intrusion path used by threat actors in production attacks.

The incident increases pressure on buyers evaluating TeamCity against GitHub Actions, GitLab CI/CD, Jenkins, CircleCI, and Azure DevOps to compare not only CI/CD features but also vulnerability-response speed, network isolation options, credential handling, and software-supply-chain controls. Organizations considering TeamCity should distinguish the security posture of on-premises deployments from hosted alternatives rather than assuming a vendor patch alone removes supply-chain risk.

Buyers may increase spending on CI/CD posture management, secrets scanning, privileged-access management, and isolated build infrastructure to reduce the blast radius of a compromised CI/CD platform.

CISA reported 10 newly confirmed exploited vulnerabilities in seven days

A weekly tracker citing CISA catalog activity reported 10 vulnerabilities crossing into confirmed in-the-wild exploitation during the past seven days, spanning nine vendors including Microsoft, MikroTik, WordPress, and WSO2.

The most relevant enterprise-specific addition is CVE-2026-5430, a critical authentication-bypass vulnerability affecting multiple products from enterprise software provider WSO2. WSO2 products compete with enterprise API-management, identity, integration, and application-platform offerings from Broadcom, IBM, Microsoft, MuleSoft, Kong, and Oracle.

Buyers should add WSO2 instances to vulnerability-management inventories and verify whether internet-facing identity, API, or integration components are exposed. More broadly, the pace of KEV additions supports funding external attack-surface management and vulnerability-prioritization tools rather than relying on CVSS scores or periodic scanning alone.

A KEV-driven remediation program requires operational capacity—asset discovery, emergency change windows, compensating controls, and credential rotation—not just additional scanner licenses. The actionable fact is CISA's classification of active exploitation, which moves remediation from routine maintenance to incident response.

ConnectWise ScreenConnect remains a recurring managed-service-provider risk

CISA added CVE-2026-84869, a CVSS 9.9 ConnectWise ScreenConnect vulnerability, to its KEV catalog on September 11 after confirming exploitation in the wild. The flaw involves improper privilege management and missing authorization, allowing attackers to transfer and execute files through an active remote session without authorization or host confirmation.

ConnectWise released a patch on September 8. The company has now had four ScreenConnect flaws added to CISA's KEV catalog since 2024, with two linked to ransomware groups.

This matters especially to enterprises using managed service providers, outsourced IT, or remote-support tools. A compromised remote-management platform can provide attackers with broad lateral access across many customer environments, making vendor concentration and MSP access a material enterprise-risk issue.

ScreenConnect competes with N-able, Datto, AnyDesk, TeamViewer, BeyondTrust, and Microsoft remote-management tools. Procurement teams should require evidence of tenant isolation, rapid emergency patching, session approval controls, administrator MFA, detailed session logging, and customer notification procedures. The repeated KEV presence shifts the buying conversation from feature parity and per-technician pricing toward blast-radius containment and third-party operational resilience.

Ransomware activity remains elevated

Recent threat-intelligence reporting cited 1,042 ransomware attacks in a reporting period, described as nearly double the comparable August 2025 figure, with average weekly cyberattacks increasing 22% year over year to 2,422 attacks per organization. Bitdefender separately reported 1,000 claimed ransomware victims during August 2026 in its monthly analysis.

These are not identical measures—one counts reported attacks and the other claimed victims—so they should not be combined into a single incident total. They nevertheless indicate sustained ransomware pressure.

The data strengthens the position of vendors selling endpoint detection and response, identity-threat detection, immutable backup, recovery orchestration, and ransomware warranties, including CrowdStrike, Microsoft, SentinelOne, Sophos, Palo Alto Networks, Rubrik, Cohesity, and Veeam.

Enterprises are likely to justify spending on recovery-time objectives, offline or immutable backups, privileged-identity controls, and tabletop exercises. Buyers should request methodology from vendors before using headline victim counts to set budgets, because claimed victims, observed attacks, and confirmed breaches measure different things. The most defensible budget case is not a vendor's attack-count estimate but the organization's own potential downtime, restoration cost, regulatory exposure, and ability to rebuild compromised identity and build systems.

What to watch

Patch or isolate TeamCity On-Premises and rotate credentials available to build agents. Search CISA's KEV catalog for all internet-facing products, prioritizing authentication bypass, remote-code-execution, VPN, virtualization, and remote-management flaws. Review MSP and remote-support access, particularly ScreenConnect deployments, for session approval controls and tenant isolation. Budget for operational capacity to respond to KEV additions within CISA's remediation windows, not just vulnerability-scanning licenses.

cybersecurityransomwareCISAvulnerability managementCI/CD security

Technology decisions, clearly explained.

Weekly analysis of the tools, platforms, and strategies that matter to B2B technology buyers. No fluff, no vendor spin.

More in Cybersecurity