Attackers Breach JetBrains Cloud Coding Service and Expose Credentials
JetBrains confirmed that an unpatched TeamCity flaw exposed Cadence users’ code and secrets. Former users should rotate credentials and review connected systems.
Reader edition
JetBrains confirmed that an unpatched TeamCity flaw exposed Cadence users’ code and secrets. Former users should rotate credentials and review connected systems.
Unit 42 traced an AI-assisted ransom intrusion across web, repository, secrets, CI/CD and cloud systems in less than 10 hours. These behaviors can reveal the loop.
D-Link fixed a DIR-X1860Z flaw that lets a local-network user set a new admin password; the similar DIR-X1860 has no update path.
Recovered tooling shows how forged WebDAV requests exposed nuclear records and credentials, with specific version, request-pattern, and signing-key checks for defenders.
Five exposed SecFlow workspaces linked Claude, Qwen and DeepSeek to Asian government and education intrusions involving credential theft, webshells, and implants.
Microsoft observed fake IT support sessions progress from Teams remote control to a persistent JavaScript implant and WinRM movement toward domain controllers.
Chrome 152.0.7977.82/.83 fixes an exploited V8 type-confusion flaw. Google has not disclosed the attackers, targets, exploit chain, or scale.
A server tied to The Gentlemen exposed TukTuk C2, a credential-stealing prompt, EDR-killer research, exfiltrated Jira data, and healthcare credentials.
Fortinet traced one stolen AWS administrator key through a new IAM user, Marketplace agreements, and billable Bedrock model calls.
A fail-open agent dashboard exposed one public-model key for three weeks, while noisy usage signals and absent spend limits delayed recognition.
Socket found 19 browser extensions using automatic updates, rotating command servers and injected modules to steal wallet secrets, sessions and passwords.
SonicWall confirmed active attacks against two SMA1000 flaws and told customers to hotfix, seek an IoC review, and rebuild systems when compromise is found.
Mandiant traced BREEZE COMET from vishing, rogue branch hardware and stolen cloud credentials to payment APIs used for hundreds of fraudulent transfers.