CISA has warned that ransomware operators are exploiting a critical JetBrains TeamCity vulnerability that was patched in July, according to BleepingComputer. The warning shifts the issue from routine patch management to an active-exploitation response: organizations using the affected build-server software should immediately confirm their exposure and remediation state.

Build systems are high-value targets because they often connect to source repositories, signing keys, deployment credentials, and production environments. A compromise can therefore become a supply-chain incident rather than remaining isolated to one server. Security teams should identify TeamCity instances, apply the current vendor guidance, restrict administrative and build-server access, and check whether the service is internet accessible.

Defenders should also review logs and endpoint telemetry for signs of unexpected administrative actions, new accounts, suspicious build configurations, or credential use. If there is evidence of compromise, follow the organization’s incident-response process and rotate credentials that could have been accessible from the server.

Source: BleepingComputer.

By Allan