daily cyber × ai intelligence

index

tagged

[CVE-2026-63077]

5 editions · 5 items

September 7, 2026

  • JetBrains is telling Cadence users to revoke and rotate every credential and secret and to treat all executions, inputs and outputs as untrusted, after attackers exploited CVE-2026-63077 (CVSS 9.8, deserialization to unauthenticated OS command execution) against a TeamCity server in JetBrains' own environment. The flaw has been in CISA's KEV catalog since 5 August; JetBrains discovered the intrusion on 23 August. The actor reached a 2024 Cadence backup and storage containing current-user data — usernames, real names, email addresses, last-login timestamps and last-accessed IPs, project source code and credentials — and defenders should hunt authentication activity using Cadence-stored credentials from 8 August onward (The Hacker News). · CI/CD & Identity

in The Diff Is the Disclosure: MikroTik's Silent Patch Comes Apart

July 29, 2026

  • JetBrains TeamCity On-Premises got a critical unauth OS-command-execution fix (CVE-2026-63077, CVSS 9.8) across all versions — a high-value target given its position in build pipelines (The Hacker News). Separately, OpenWrt 24.10.8 closes a critical DHCPv6 stack overflow (CVE-2026-53921, CVSS 9.8) letting an unauthenticated attacker on the network run code as root through odhcpd (The Hacker News). · Vulnerabilities & Exploits

in Artifactory Zero-Days Confirmed as the Hugging Face AI Agent's Escape Route