SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefFriday, August 07, 2026 INTEL CONFIDENCE 70% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Active Exploitation of Critical JetBrains TeamCity Vulnerability | CRITICAL |
|
5 C2 IPs | 0 OTX IOCs | 39 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is highlighted by active exploitation of a critical JetBrains TeamCity vulnerability (CVE-2026-63077) and critical patches from Cisco for SD-WAN and IOS XE. Additionally, hardware-level threats persist with new Spectre v2 bypasses (TONTOU and Interrupt Injection) targeting Linux systems on Intel and AMD CPUs. Meanwhile, threat actors are leveraging ClickFix campaigns to deliver macOS infostealers, while AI technologies introduce novel risks including token jacking and AI recommendation poisoning. |
|
■ CRITICAL STORIES Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability Attackers have begun active exploitation of CVE-2026-63077, a critical unauthenticated remote code execution vulnerability in JetBrains TeamCity, posing an immediate threat to CI/CD pipelines. |
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs Cisco released critical updates addressing severe vulnerabilities, including three CVSS 9.8 bugs, in Catalyst SD-WAN and IOS XE Software that could allow remote code execution or complete system takeover. |
Swiss government SharePoint breach compromised 200 accounts Threat actors successfully breached Swiss federal IT systems by exploiting vulnerabilities in Microsoft SharePoint, leading to the compromise of approximately 200 accounts and highlighting the ongoing risk to government infrastructure. |
New TONTOU CPU Attack and Interrupt Injection Bypass Spectre v2 Defenses Researchers have disclosed new hardware-level attacks that bypass Spectre v2 mitigations on Intel and AMD CPUs, allowing unprivileged local attackers to leak Linux kernel secrets and password hashes. |
|
■ CVEs IDENTIFIED CVE-2026-63077 JetBrains TeamCity — Unauthenticated Remote Code Execution |
[CVE-TBD] Cisco Catalyst SD-WAN / IOS XE Software — Remote Code Execution and Privilege Escalation (Three 9.8 CVSS bugs) |
[CVE-TBD] Microsoft SharePoint — Server breach and account compromise (Swiss Gov) |
[CVE-TBD] Linux Kernel (Zapscape KVM Flaw) — L1 Guest VM escape to Linux host |
|
■ THREAT ACTORS Linked to BlackFile; targeting hedge funds, private-equity firms, and financial organizations with extortion attacks. |
Ransom Cartel | Ransomware Group |
Mastermind Maksim Silnikau sentenced to 16 years; historically active in ransomware and Angler EK distribution. |
Connor Riley Moucka | Individual |
Snowflake extortionist who pleaded guilty to hacking and extorting over 165 organizations. |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Exploitation of CVE-2026-63077 in JetBrains TeamCity and SharePoint vulnerabilities. |
| T1195.002 | | Supply Chain Compromise: Compromising Software Dependencies | ChainDrop self-propagating npm worm. |
| T1204.002 | | User Execution: Malicious File | ClickFix attacks tricking macOS users into running Go-based infostealers. |
| T1539 | | Steal Web Session Cookie | Infostealer targeting browser-stored passwords and credentials. |
| T1555.001 | | Credentials from Web Browsers | Infostealer extracting passwords and Apple Keychain data. |
| T1068 | | Exploitation for Privilege Escalation | Zapscape KVM guest-to-host escape and Spectre v2 bypasses. |
|
■ PATCH PRIORITY CRITICAL — JetBrains TeamCity — Active exploitation of CVE-2026-63077 (RCE) — SecurityWeek |
CRITICAL — Cisco Catalyst SD-WAN / IOS XE Software — Three CVSS 9.8 bugs allowing RCE/PE — The Hacker News |
CRITICAL — Paperclip — Critical flaw allowing admin access and code execution — SecurityWeek |
HIGH — Microsoft SharePoint — Vulnerabilities exploited to breach Swiss government accounts — BleepingComputer |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch JetBrains TeamCity immediately to remediate CVE-2026-63077 to prevent unauthenticated remote code execution. |
| 2 | [P1] Apply security updates released by Cisco for Catalyst SD-WAN, IOS XE, and FMC to address the three critical CVSS 9.8 vulnerabilities. |
| 3 | [P2] Audit and restrict external access to Rockwell Automation PLCs, especially those connected via mobile carrier networks, to mitigate unauthorized access. |
| 4 | [P2] Update deployments using the CryptoJS library to replace CryptoJS.lib.WordArray.random() with a secure, cryptographically strong pseudo-random number generator (CSPRNG). |
| 5 | [P3] Implement host-level mitigations and monitor for speculative execution side-channel indicators on Linux systems running Intel and AMD CPUs to defend against TONTOU and Interrupt Injection attacks. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |