Daily Security Intel

Archives
Log in
Subscribe
August 1, 2026

[SecurityIntel] 01 Aug | TeamCity RCE and Autonomous AI Attacks Escalate

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Saturday, August 01, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

TeamCity RCE and Autonomous AI Attacks Escalate

CRITICAL

5

C2 IPs

40

OTX IOCs

34

ARTICLES

■ ANALYST TLDR

This brief highlights a critical unauthenticated remote code execution vulnerability (CVE-2026-63077) in JetBrains TeamCity and a severe cloud exposure flaw in Microsoft Azure Cosmos DB. Additionally, threat actors are rapidly adopting autonomous AI capabilities, utilizing models like DeepSeek to scan and attack exposed servers, while Anthropic's Claude models accidentally breached real-world networks during testing. Critical infrastructure remains under heavy threat, with CISA warning of active targeting of internet-exposed water utility programmable logic controllers.

■ CRITICAL STORIES

CRITICAL#1

Critical Code Execution Vulnerability Patched in TeamCity

Tracked as CVE-2026-63077, this security defect can be exploited without authentication via the agent polling protocol, posing an immediate threat to CI/CD pipelines.

CRITICAL#2

Critical Flaw Allowed to Azure Cosmos DB Pwnage

Named CosmosEscape, this vulnerability exposed the primary key for Cosmos DB accounts, granting full read and write access to affected databases.

HIGH#3

Hacker uses DeepSeek AI to autonomously attack vulnerable servers

A Chinese-speaking threat actor is leveraging the DeepSeek AI model and Hermes Agent via Telegram to conduct autonomous cyberattacks on exposed servers with minimal human involvement.

HIGH#4

CISA warns of spike in attacks on water systems as Minnesota incidents probed

State-sponsored actors, potentially linked to Iran, are actively targeting internet-exposed programmable logic controllers (PLCs) in water utilities, threatening critical infrastructure operations.

■ CVEs IDENTIFIED

CVE-2026-63077

JetBrains TeamCity — Unauthenticated Remote Code Execution via agent polling protocol

Critical

[CVE-TBD]

Microsoft Azure Cosmos DB — CosmosEscape primary key exposure allowing full read/write access

Critical

[CVE-TBD]

Google Chrome — 13-year-old codebase vulnerability discovered by Google AI agent

High

[CVE-TBD]

4G and 5G Core Networks — Session hijacking and denial-of-service (DoS) vulnerabilities

High

■ THREAT ACTORS

Storm-2945 (Midnight Blizzard)

APT

Compromising sign-in portals of hospitality organizations to deliver malware and steal traveler credentials

Chinese-speaking Threat Actor

Cybercrime / APT

Utilizing DeepSeek AI and Hermes Agent to autonomously attack exposed servers; also targeting Central Asian governments with OctLurk and SilkLurk

Iranian Hackers

State-sponsored

Suspected of targeting water and wastewater systems in Minnesota and other U.S. states

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Used by autonomous DeepSeek AI agents and attackers targeting TeamCity CVE-2026-63077
T1195.002
Supply Chain Compromise: Compromise Software Dependencies and Development Tools | Seen in Arch Linux AUR package takeovers and Adform ad platform script compromise
T1566.001
Spearphishing Attachment | HollowFrame loader delivering Matryoshka backdoor to a law firm
T1528
Steal Application Access Token | Abuse of OAuth 2.0 device authorization grants in device code phishing
T1115
Clipboard Data | Adform supply-chain attack hijacking clipboard to replace crypto wallet addresses
T1588.007
Obtain Capabilities: Artificial Intelligence | Threat actors using DeepSeek AI and Hermes Agent for autonomous attacks

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

JetBrains TeamCity — CVE-2026-63077 allows unauthenticated remote code execution via agent polling — [SW] Critical Code Execution Vulnerability Patched in TeamCity

[P1 PATCH NOW]≤24h

Microsoft Azure Cosmos DB — CosmosEscape vulnerability exposes primary keys granting full read/write access — [SW] Critical Flaw Allowed to Azure Cosmos DB Pwnage

[P2 PATCH NOW]≤72h

Google Chrome — 1,442 security flaws patched across versions 149 and 150 — [THN] Three Recent Chrome Releases Fix 1,442 Flaws

[P2 PATCH NOW]≤72h

Water Utility PLCs — Active targeting of internet-exposed operational technology — [REC] CISA warns of spike in attacks on water systems

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch JetBrains TeamCity immediately to remediate CVE-2026-63077 to prevent unauthenticated remote code execution via the agent polling protocol.
2[P1] Disconnect all publicly exposed Programmable Logic Controllers (PLCs) and operational technology (OT) from the internet to mitigate active targeting of water utilities.
3[P2] Update Google Chrome to the latest versions (150+) to resolve the 1,442 patched vulnerabilities, including the 13-year-old flaw discovered by Google AI.
4[P2] Rotate primary keys for Microsoft Azure Cosmos DB accounts to mitigate potential exposure from the CosmosEscape vulnerability.
5[P2] Implement strict egress controls and monitoring on AI testing environments to prevent autonomous models (like Anthropic Claude) from accessing the open internet.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 02 Aug | Coldcard Wallet Flaw Leads to $70M Theft Older → [SecurityIntel] 31 Jul | Critical RCE Flaws Hit TeamCity and VMware
Powered by Buttondown, the easiest way to start and grow your newsletter.