Update now! JetBrains TeamCity vulnerability abused at scale

JetBrains issued a warning on March 4, 2024 about two serious vulnerabilities in TeamCity server. The flaws can be used by a remote, unauthenticated attacker with HTTP(S) access to a TeamCity on-premises server to bypass authentication checks and gain administrative Read More …

Alleged FruitFly malware creator ruled incompetent to stand trial

On January 4, 2017, Case Western Reserve University (CWRU), located in Cleveland, Ohio, became aware of an infection on more than 100 of its computers. The university was notified by an undisclosed third party, who provided information to help the Read More …

Hundreds of museums hit by cyber attack

Hundreds of art institutions and museums have been affected by a cyber attack on the Gallery Systems software company, with those impacted having used the software to organise their online archives. Last month, Gallery Systems informed its clients that computers Read More …

Three New Malicious PyPI Packages Deploy CoinMiner on Linux Devices

On December 5th, 2023, FortiGuard’s AI-driven OSS malware detection system identified three intriguing PyPI (Python Package Index) packages. These packages, upon initial use, deploy a CoinMiner executable on Linux devices. Leveraging our historical malware database, Fortinet researchers noted that the Read More …

Russian Foreign Intelligence Service (SVR) Exploiting JetBrains TeamCity CVE Globally

The US Federal Bureau of Investigation (FBI) and partners assess Russian Foreign Intelligence Service (SVR) cyber actors – also known as Advanced Persistent Threat 29 (APT 29), the Dukes, CozyBear, and NOBELIUM/Midnight Blizzard – are exploiting CVE-2023-42793 a at a Read More …

NATO: The NCI Agency’s new data science and AI tool receives security accreditation

Scientists, artificial intelligence (AI) and cyber security experts from the NATO Communications and Information Agency (NCI Agency) celebrated a new milestone at the NCI Agency’s campus in The Hague, Netherlands, after the security accreditation of a high performance computing environment Read More …

EU agrees ‘historic’ deal with world’s first laws to regulate AI

The world’s first comprehensive laws to regulate artificial intelligence have been agreed in a landmark deal after a marathon 37-hour negotiation between the European Parliament and EU member states. The agreement was described as “historic” by Thierry Breton, the European Read More …

Why Both C-Suite Executives and Technical Experts Need to Take Memory Safe Coding Seriously

Memory safety vulnerabilities are the most prevalent type of disclosed software vulnerability. They are a class of well-known and common coding errors that malicious actors routinely exploit. These vulnerabilities represent a major problem for the software industry as they cause Read More …

Roblox and Twitch provider Tipalti breached by ransomware

Accounting software provider Tipalti says it is investigating a claim by ransomware group ALPHV that they have gained access to Tipalti’s systems. Tipalti makes software for accounting and payment automation and has some big names among its customers. In what Read More …

Hijackable Go Module Repositories

The Go module ecosystem is unique because it’s decentralized. Other packaging systems like Pypi or NPM require developers to create accounts to upload their packages. This gives the package platform the ability to moderate users and content. That isn’t the Read More …