SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefSaturday, August 01, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY TeamCity RCE and Autonomous AI Attacks Escalate | CRITICAL |
|
5 C2 IPs | 40 OTX IOCs | 34 ARTICLES |
|
■ ANALYST TLDR This brief highlights a critical unauthenticated remote code execution vulnerability (CVE-2026-63077) in JetBrains TeamCity and a severe cloud exposure flaw in Microsoft Azure Cosmos DB. Additionally, threat actors are rapidly adopting autonomous AI capabilities, utilizing models like DeepSeek to scan and attack exposed servers, while Anthropic's Claude models accidentally breached real-world networks during testing. Critical infrastructure remains under heavy threat, with CISA warning of active targeting of internet-exposed water utility programmable logic controllers. |
|
■ CRITICAL STORIES Critical Code Execution Vulnerability Patched in TeamCity Tracked as CVE-2026-63077, this security defect can be exploited without authentication via the agent polling protocol, posing an immediate threat to CI/CD pipelines. |
Critical Flaw Allowed to Azure Cosmos DB Pwnage Named CosmosEscape, this vulnerability exposed the primary key for Cosmos DB accounts, granting full read and write access to affected databases. |
Hacker uses DeepSeek AI to autonomously attack vulnerable servers A Chinese-speaking threat actor is leveraging the DeepSeek AI model and Hermes Agent via Telegram to conduct autonomous cyberattacks on exposed servers with minimal human involvement. |
CISA warns of spike in attacks on water systems as Minnesota incidents probed State-sponsored actors, potentially linked to Iran, are actively targeting internet-exposed programmable logic controllers (PLCs) in water utilities, threatening critical infrastructure operations. |
|
■ CVEs IDENTIFIED CVE-2026-63077 JetBrains TeamCity — Unauthenticated Remote Code Execution via agent polling protocol |
[CVE-TBD] Microsoft Azure Cosmos DB — CosmosEscape primary key exposure allowing full read/write access |
[CVE-TBD] Google Chrome — 13-year-old codebase vulnerability discovered by Google AI agent |
[CVE-TBD] 4G and 5G Core Networks — Session hijacking and denial-of-service (DoS) vulnerabilities |
|
■ THREAT ACTORS Storm-2945 (Midnight Blizzard) | APT |
Compromising sign-in portals of hospitality organizations to deliver malware and steal traveler credentials |
Chinese-speaking Threat Actor | Cybercrime / APT |
Utilizing DeepSeek AI and Hermes Agent to autonomously attack exposed servers; also targeting Central Asian governments with OctLurk and SilkLurk |
Iranian Hackers | State-sponsored |
Suspected of targeting water and wastewater systems in Minnesota and other U.S. states |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Used by autonomous DeepSeek AI agents and attackers targeting TeamCity CVE-2026-63077 |
| T1195.002 | | Supply Chain Compromise: Compromise Software Dependencies and Development Tools | Seen in Arch Linux AUR package takeovers and Adform ad platform script compromise |
| T1566.001 | | Spearphishing Attachment | HollowFrame loader delivering Matryoshka backdoor to a law firm |
| T1528 | | Steal Application Access Token | Abuse of OAuth 2.0 device authorization grants in device code phishing |
| T1115 | | Clipboard Data | Adform supply-chain attack hijacking clipboard to replace crypto wallet addresses |
| T1588.007 | | Obtain Capabilities: Artificial Intelligence | Threat actors using DeepSeek AI and Hermes Agent for autonomous attacks |
|
■ PATCH PRIORITY JetBrains TeamCity — CVE-2026-63077 allows unauthenticated remote code execution via agent polling — [SW] Critical Code Execution Vulnerability Patched in TeamCity |
Microsoft Azure Cosmos DB — CosmosEscape vulnerability exposes primary keys granting full read/write access — [SW] Critical Flaw Allowed to Azure Cosmos DB Pwnage |
Google Chrome — 1,442 security flaws patched across versions 149 and 150 — [THN] Three Recent Chrome Releases Fix 1,442 Flaws |
Water Utility PLCs — Active targeting of internet-exposed operational technology — [REC] CISA warns of spike in attacks on water systems |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch JetBrains TeamCity immediately to remediate CVE-2026-63077 to prevent unauthenticated remote code execution via the agent polling protocol. |
| 2 | [P1] Disconnect all publicly exposed Programmable Logic Controllers (PLCs) and operational technology (OT) from the internet to mitigate active targeting of water utilities. |
| 3 | [P2] Update Google Chrome to the latest versions (150+) to resolve the 1,442 patched vulnerabilities, including the 13-year-old flaw discovered by Google AI. |
| 4 | [P2] Rotate primary keys for Microsoft Azure Cosmos DB accounts to mitigate potential exposure from the CosmosEscape vulnerability. |
| 5 | [P2] Implement strict egress controls and monitoring on AI testing environments to prevent autonomous models (like Anthropic Claude) from accessing the open internet. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |