Ransomware Gangs Exploit TeamCity Flaw, CISA Warns
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that ransomware groups are actively exploiting a critical vulnerability in JetBrains TeamCity that was patched in July. The agency’s advisory, issued on Wednesday, confirms that threat actors are targeting organizations that have not applied the fix.
TeamCity is a continuous integration and delivery (CI/CD) tool used by many software development teams to automate builds and deployments. The flaw, identified as CVE‑2023‑42739, allowed unauthenticated attackers to execute arbitrary code on the server. JetBrains released a patch in July, but CISA’s notice indicates that many federal and private networks remain exposed because the update has not been installed.
Ransomware gangs are leveraging the weakness to gain a foothold in victim environments, then encrypting files and demanding payment. The agencies most at risk are those that run TeamCity on internal servers without timely patch management. The advisory does not suggest new malware variants, only that existing ransomware operators have added this exploit to their playbook.
To protect against this threat, organizations should verify that the July 2023 TeamCity patch is applied to all instances. Administrators should also review firewall rules to limit external access to CI/CD servers and enable multi‑factor authentication for any accounts that can manage builds. Regularly scanning for unexpected processes and using endpoint detection tools can help spot malicious activity early.
ComputerScams.com offers free vulnerability scanners and a password security checker that can help you confirm whether your systems are up to date. Running these tools periodically is a simple way to catch missed patches before attackers can exploit them.
The key takeaway is to treat the TeamCity patch as a priority update. Apply it immediately, restrict network access to the service, and monitor for unusual behavior. Prompt action can stop ransomware gangs from turning a known flaw into a ransomware attack.
Source: Read the original report
Safety tip: Check your TeamCity servers today and install the latest security update if it is missing.