Critical TeamCity RCE Flaw Threatens CI/CD Servers
Rapid7 details critical TeamCity flaw CVE-2026-63077, which lets unauthenticated attackers run commands on exposed on-premises CI/CD servers worldwide.
Read more →Latest cybersecurity news, vulnerabilities, and threat intelligence
Rapid7 details critical TeamCity flaw CVE-2026-63077, which lets unauthenticated attackers run commands on exposed on-premises CI/CD servers worldwide.
Read more →
Zero-click prompt injection tests hijacked agentic AI browsers, exposing authenticated sessions to phishing, data theft and unauthorized account actions.
Read more →
CISA adds exploited Langflow, N-central and Tomcat flaws to its KEV catalog, giving federal agencies until August 7 to apply vendor mitigations.
Read more →
ChainDrop compromised hundreds of npm packages tied to Keyv and Cacheable, stealing developer credentials and spreading through trusted publishing access.
Read more →
CaptiveCrunch hijacks hotel Wi-Fi traffic to steal Microsoft 365 access and deliver CornFlake surveillance malware, Microsoft warns travelers worldwide.
Read more →
CaptiveCrunch hijacks hotel Wi-Fi traffic to steal Microsoft 365 access and deliver CornFlake surveillance malware, Microsoft warns travelers worldwide.
Read more →
Coldcard's weak seed generation flaw is linked to suspected thefts of $88.6 million in bitcoin, with affected wallet owners urged to migrate funds now.
Read more →
Cloudways reports a wp2shell variant hiding the WordPress batch route in POST bodies, bypassing URL-only defenses and reinforcing the need to patch now.
Read more →
CISA warns utilities to disconnect exposed PLCs after cyberattacks targeted more than 30 Minnesota water systems, disrupting some automated controls.
Read more →
Laundry Bear is deploying OWAReaper through an Exchange OWA flaw to keep persistent mailbox access across government and critical industry targets in Europe.
Read more →