Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

A Critical Flaw in TeamCity Exposes Organizations to Remote Code Execution Attacks Researchers have discovered a severe vulnerability in JetBrains’ popular continuous integration and continuous deployment (CI/CD) tool, TeamCity. The flaw, which affects versions 2020.1 and later, allows attackers to execute arbitrary operating system commands on compromised systems without requiring login credentials. The vulnerability is … Read more

Google Adopts New Threat Actor Naming System

Google has introduced a new system for naming threat actors, moving away from sequential numbers and disparate identifiers in favor of a cryptonym-based convention. This shift aims to simplify tracking and facilitate comparisons across different organizations. The new naming scheme uses two-word combinations, with the first word being a unique term that may have been … Read more

Data breach at medical billing firm MCBS affects 1.26 million people

A massive data breach at a medical billing firm has left over 1.26 million people’s sensitive information exposed, highlighting the continued vulnerability of healthcare organizations to cyber threats. Medical Computer Business Services (MCBS), a regional private medical billing and practice-management company based in Augusta, Georgia, disclosed that a network breach occurred between September 22 and … Read more

Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost

Microsoft’s latest announcement reveals that its cutting-edge cybersecurity AI model has achieved an impressive 95.95% detection rate for malicious activity, dubbed MDASH (Malicious Detection and Analysis Security Hybrid). Moreover, this breakthrough innovation promises to slash costs by half compared to traditional methods. The implications are significant: with AI-driven threat detection on the rise, organizations must … Read more

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

A Linux Traffic-Control Race Becomes the Latest Exploit, Thanks to AI-Powered Research A vulnerability in the Linux kernel’s traffic-control system has been found and exploited by hackers, leaving numerous users vulnerable to remote code execution attacks. The exploit was discovered through a combination of machine learning algorithms and human research efforts. The vulnerability, dubbed “TCPdump,” … Read more

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

A Critical Vulnerability in TeamCity Exposes Organizations to Remote Code Execution Attacks A newly discovered flaw in JetBrains’ TeamCity, a popular continuous integration and continuous deployment (CI/CD) tool, has left hundreds of thousands of users vulnerable to remote code execution attacks. The critical vulnerability, which affects versions 2020.3 and earlier, allows attackers to run operating … Read more

Origin Energy Data Breach Affects 900,000 Australians

Origin Energy Data Breach Exposes 900,000 Australians to Cyber Threats A major data breach at Australian energy giant Origin Energy has compromised sensitive information for nearly a million customers. The incident highlights the growing threat of cyber attacks against critical infrastructure and the importance of vigilance in protecting personal data. The breach, which was discovered … Read more

Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day

A Critical Vulnerability in Arista’s VeloCloud Orchestrator Platform Has Been Exploited in the Wild In a stark reminder of the ongoing threat landscape, Arista Networks has released patches for a critical-severity vulnerability affecting its VeloCloud Orchestrator (VCO) centralized management platform. The security flaw, tracked as CVE-2026-16812, has already been exploited by attackers as a zero-day, … Read more

Unpatched Fastjson Vulnerability Exploited in Attacks

A critical vulnerability in the popular Fastjson library is being exploited by threat actors to execute arbitrary code on vulnerable servers, posing a significant risk to data confidentiality, integrity, and availability. The issue affects all deployments running as Spring Boot executable fat-jars, which are widely used in various sectors, including business, computing, financial services, healthcare, … Read more

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

Cybersecurity researchers have identified a critical vulnerability in the Arista VeloCloud Orchestrator, a software tool used for network management and orchestration. Attackers have been exploiting this flaw to inject malicious commands, potentially leading to unauthorized access and data breaches. The issue arises from a command injection bug that allows attackers to bypass security measures and … Read more