A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
The vulnerability in question is CVE-2026-63077 (CVSS score: 9.8), a case of deserializati...
Tracked as CVE-2026-63077, the critical bug can be exploited without authentication for remote code execution.
The post Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability appeared first on SecurityWeek.
Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts.
The intrusions reached at least 165 organizations and exposed records belonging to at lea...
The OWASP GenAI Security Project has released the 2026 edition of its Top 10 for LLM Applications and, for the first time, the list was influenced by real-world incidents. The two top entries – Prompt Injection and Sensitive Information Disclosure – remained constant, but the order shifted more than...
Snowflake hacker Connor Moucka pleads guilty after breaching 165 organizations, stealing billions of records, and extorting victims. Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty this week to a computer hacking conspiracy that compromised over 165 organizations, stole billions of cu...
In this interview with Help Net Security, Rui Ribeiro, CEO of Jscrambler, explains why the browser has become a security problem organizations do not control. Companies do not own the device, the extensions, or the network path, yet that is where application logic, third-party code, customer data, a...
Cybercriminals and state-backed hacking groups are abusing trusted identities, cloud services, AI tools, and software supply chains to gain access while avoiding detection, according to CrowdStrike’s 2026 Threat Hunting Report. Intrusion activity increased by about 4% over the past year. Even though...
It’s just a remote maintenance function, says Zbtlink
A backup job fires at two in the morning. A scanner walks the same AWS account an hour later, a deployment pipeline assumes a role at four, and a logging agent runs straight through the night. Each of those actions carries a credential issued to a machine. An attacker holding one of those credential...
Cloudflare open sourced Cloudflare OS, the agent platform whose first version its own employees have used since May. Every resource an agent reads gets recorded, the record follows whatever the agent produces, and when a second person opens that output the platform checks them against the underlying...
President Donald Trump has talked with Chinese President Xi Jinping about Southeast Asian scam compounds, a State Department official told senators at a hearing on the transnational issue.
Georgia's State Security Service is investigating whether foreign entities were behind the spread of fabricated stories claiming that Georgians were mistreating Russian tourists.
Guide pratique mkcert sur Debian : créez votre autorité de certification locale et générez des certificats HTTPS reconnus par vos navigateurs.
Le post mkcert : créer des certificats HTTPS valides en local sur Debian a été publié sur IT-Connect.
It started with an 'impossible task' and led to AI deciding it needed to act as a collective intelligence
At the Black Hat security conference, the AI giant revealed new details about how its agents went rogue, hacked several other companies—and did it all right under the company’s nose.
[This is a Guest Diary by Daryl Jiminez, an ISC intern as part of the SANS.edu BACS program]
La ville de Lancaster, Ohio, a dû mettre hors ligne ses ordinateurs municipaux le 6 août suite à des alertes de rançongiciel sur plusieurs machines. Bien que les systèmes essentiels (911, eau, etc.) n'aient pas été directement affectés, l'incident a entraîné des perturbations. Le 28 août, un comité...
Ambition DX Holdings a été victime d'un accès non autorisé à son serveur de fichiers, entraînant la confirmation d'une fuite de certaines informations. Les données potentiellement compromises incluent des informations personnelles (noms, adresses, numéros de téléphone, adresses e-mail) de clients, d...