daily cyber × ai intelligence

index

tagged

[jetbrains]

10 editions · 7 items

September 7, 2026

  • JetBrains is telling Cadence users to revoke and rotate every credential and secret and to treat all executions, inputs and outputs as untrusted, after attackers exploited CVE-2026-63077 (CVSS 9.8, deserialization to unauthenticated OS command execution) against a TeamCity server in JetBrains' own environment. The flaw has been in CISA's KEV catalog since 5 August; JetBrains discovered the intrusion on 23 August. The actor reached a 2024 Cadence backup and storage containing current-user data — usernames, real names, email addresses, last-login timestamps and last-accessed IPs, project source code and credentials — and defenders should hunt authentication activity using Cadence-stored credentials from 8 August onward (The Hacker News). · CI/CD & Identity

in The Diff Is the Disclosure: MikroTik's Silent Patch Comes Apart

July 29, 2026

  • JetBrains TeamCity On-Premises got a critical unauth OS-command-execution fix (CVE-2026-63077, CVSS 9.8) across all versions — a high-value target given its position in build pipelines (The Hacker News). Separately, OpenWrt 24.10.8 closes a critical DHCPv6 stack overflow (CVE-2026-53921, CVSS 9.8) letting an unauthenticated attacker on the network run code as root through odhcpd (The Hacker News). · Vulnerabilities & Exploits

in Artifactory Zero-Days Confirmed as the Hugging Face AI Agent's Escape Route

June 21, 2026

FortiBleed Exposes 86,000 FortiGate Devices as North Korea's Sapphire Sleet Poisons the Mastra npm Catalog

Fortinet networks face massive credential exposure via FortiBleed affecting 86,644 devices, while North Korea's Sapphire Sleet compromised 145 Mastra npm packages with an infostealer, and Google Cloud Vertex AI SDK suffered a cross-tenant RCE vulnerability. Critical CVEs in Splunk, NGINX, Cisco SD-WAN, and Joomla are under active exploitation, alongside emerging AI-focused attacks including AutoJack and malicious JetBrains plugins stealing API keys.

June 20, 2026

FortiBleed Burns 86,000 FortiGate Devices as Novo Nordisk Loses 1.3TB — Including AI Models — to a Leaked GitHub Token

FortiBleed has compromised ~86,644 internet-facing FortiGate devices in a credential-harvesting campaign, while a leaked GitHub token gave FulcrumSec access to Novo Nordisk, exfiltrating 1.3TB including unreleased drug formulas and internal AI models. Mastra npm packages were trojanized by Sapphire Sleet (North Korea–nexus), and multiple AI infrastructure flaws emerged: SearchLeak (CVE-2026-42824) in Microsoft 365 Copilot, Pickle in the Middle in Google Vertex AI, and vulnerabilities in LiteLLM. Ransomware gangs including Qilin, Gentlemen, and DragonForce continue dominating the threat landscape with EDR-killing tradecraft and cloud-based C2 abuse.

June 19, 2026

FortiBleed Burns 70,000+ Fortinet Edge Devices While a Leaked GitHub Token Guts Novo Nordisk

FortiBleed exposed working SSL-VPN credentials for 70,000+ Fortinet devices across 194 countries via industrialized hash-cracking by a Russian-speaking group, while a forgotten GitHub token cost Novo Nordisk 1.3TB of drug formulas and internal AI models. Critical vulnerabilities in NGINX (CVE-2026-42530), Cisco SD-WAN and ISE, Splunk, and Joomla are under active exploitation, alongside AI pipeline supply-chain attacks hitting Mastra, JetBrains Marketplace, and Google Vertex AI. The AtomicArch campaign compromised ~1,500 Arch Linux AUR packages with Rust infostealers and eBPF rootkits.