Daily Security Intel

Archives
Log in
Subscribe
August 7, 2026

[SecurityIntel] 07 Aug | Active Exploitation of Critical JetBrains TeamCity Vulnerability

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Friday, August 07, 2026

INTEL CONFIDENCE  70%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Active Exploitation of Critical JetBrains TeamCity Vulnerability

CRITICAL

5

C2 IPs

0

OTX IOCs

39

ARTICLES

■ ANALYST TLDR

Today's threat landscape is highlighted by active exploitation of a critical JetBrains TeamCity vulnerability (CVE-2026-63077) and critical patches from Cisco for SD-WAN and IOS XE. Additionally, hardware-level threats persist with new Spectre v2 bypasses (TONTOU and Interrupt Injection) targeting Linux systems on Intel and AMD CPUs. Meanwhile, threat actors are leveraging ClickFix campaigns to deliver macOS infostealers, while AI technologies introduce novel risks including token jacking and AI recommendation poisoning.

■ CRITICAL STORIES

INFO#1

Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability

Attackers have begun active exploitation of CVE-2026-63077, a critical unauthenticated remote code execution vulnerability in JetBrains TeamCity, posing an immediate threat to CI/CD pipelines.

INFO#2

Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs

Cisco released critical updates addressing severe vulnerabilities, including three CVSS 9.8 bugs, in Catalyst SD-WAN and IOS XE Software that could allow remote code execution or complete system takeover.

INFO#3

Swiss government SharePoint breach compromised 200 accounts

Threat actors successfully breached Swiss federal IT systems by exploiting vulnerabilities in Microsoft SharePoint, leading to the compromise of approximately 200 accounts and highlighting the ongoing risk to government infrastructure.

INFO#4

New TONTOU CPU Attack and Interrupt Injection Bypass Spectre v2 Defenses

Researchers have disclosed new hardware-level attacks that bypass Spectre v2 mitigations on Intel and AMD CPUs, allowing unprivileged local attackers to leak Linux kernel secrets and password hashes.

■ CVEs IDENTIFIED

CVE-2026-63077

JetBrains TeamCity — Unauthenticated Remote Code Execution

Critical

[CVE-TBD]

Cisco Catalyst SD-WAN / IOS XE Software — Remote Code Execution and Privilege Escalation (Three 9.8 CVSS bugs)

Critical

[CVE-TBD]

Microsoft SharePoint — Server breach and account compromise (Swiss Gov)

High

[CVE-TBD]

Linux Kernel (Zapscape KVM Flaw) — L1 Guest VM escape to Linux host

Critical

■ THREAT ACTORS

UNC6671

Threat Group

Linked to BlackFile; targeting hedge funds, private-equity firms, and financial organizations with extortion attacks.

Ransom Cartel

Ransomware Group

Mastermind Maksim Silnikau sentenced to 16 years; historically active in ransomware and Angler EK distribution.

Connor Riley Moucka

Individual

Snowflake extortionist who pleaded guilty to hacking and extorting over 165 organizations.

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Exploitation of CVE-2026-63077 in JetBrains TeamCity and SharePoint vulnerabilities.
T1195.002
Supply Chain Compromise: Compromising Software Dependencies | ChainDrop self-propagating npm worm.
T1204.002
User Execution: Malicious File | ClickFix attacks tricking macOS users into running Go-based infostealers.
T1539
Steal Web Session Cookie | Infostealer targeting browser-stored passwords and credentials.
T1555.001
Credentials from Web Browsers | Infostealer extracting passwords and Apple Keychain data.
T1068
Exploitation for Privilege Escalation | Zapscape KVM guest-to-host escape and Spectre v2 bypasses.

■ PATCH PRIORITY

[P3 PATCH NOW]≤1 week

CRITICAL — JetBrains TeamCity — Active exploitation of CVE-2026-63077 (RCE) — SecurityWeek

[P3 PATCH NOW]≤1 week

CRITICAL — Cisco Catalyst SD-WAN / IOS XE Software — Three CVSS 9.8 bugs allowing RCE/PE — The Hacker News

[P3 PATCH NOW]≤1 week

CRITICAL — Paperclip — Critical flaw allowing admin access and code execution — SecurityWeek

[P3 PATCH NOW]≤1 week

HIGH — Microsoft SharePoint — Vulnerabilities exploited to breach Swiss government accounts — BleepingComputer

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch JetBrains TeamCity immediately to remediate CVE-2026-63077 to prevent unauthenticated remote code execution.
2[P1] Apply security updates released by Cisco for Catalyst SD-WAN, IOS XE, and FMC to address the three critical CVSS 9.8 vulnerabilities.
3[P2] Audit and restrict external access to Rockwell Automation PLCs, especially those connected via mobile carrier networks, to mitigate unauthorized access.
4[P2] Update deployments using the CryptoJS library to replace CryptoJS.lib.WordArray.random() with a secure, cryptographically strong pseudo-random number generator (CSPRNG).
5[P3] Implement host-level mitigations and monitor for speculative execution side-channel indicators on Linux systems running Intel and AMD CPUs to defend against TONTOU and Interrupt Injection attacks.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
Older → [SecurityIntel] 06 Aug | CISA Warns of Exploited Langflow and Tomcat Flaws
Powered by Buttondown, the easiest way to start and grow your newsletter.