CuraSec

Act active

CISA: Ransomware gangs now exploiting critical TeamCity flaw

2026-09-24 15:49 UTC · BleepingComputer · read the source ↗ #ransomware#teamcity#cicd-security
  • Engineer — Act: TeamCity is core CI/CD infrastructure; active ransomware exploitation means immediate patching to the July release is overdue — also audit build logs and pipeline configurations for signs of unauthorized access or tampered artifacts.
  • SOC/IR — Act: With ransomware actors actively leveraging this, hunt for unusual authentication events, anomalous build triggers, or lateral movement originating from TeamCity hosts; a compromised CI/CD server is an assume-breach scenario for the entire build pipeline.
  • Leader — Act: Ransomware exploitation of CI/CD infrastructure carries supply-chain and disclosure risk — confirm whether TeamCity is run internally or by key software vendors, and brief leadership before a downstream incident surfaces the question.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.