๐ต๏ธ RESEARCH & DEEP DIVES
-
Critical JetBrains TeamCity RCE Vulnerability CVE-2026-63077 Allows Unauthenticated Attacks
CVE-2026-63077
JetBrains TeamCity On-Premises has an unauthenticated remote code execution vulnerability.- Applies to all versions of JetBrains TeamCity On-Premises prior to 2025.11.7 and 2026.1.3
- Vulnerability allows attackers to bypass authentication and execute arbitrary OS commands remotely
- Exploitation requires only HTTP/HTTPS access to the TeamCity server, no valid credentials needed
- Flaw resides in the TeamCity agent polling protocol enabling command execution with server process privileges
- Risks include exposure of credentials, build data, and injection of malicious code into software releases
๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
-
Unauthenticated RCE in Innotim Logsign SIEM Affects Versions Before 6.4.108
CVE-2026-17561
Innotim Logsign SIEM has an unauthenticated remote code execution vulnerability.- Applies to Innotim Software's Logsign SIEM versions before 6.4.108
- Vulnerability is improper control of code generation allowing code injection
- Enables unauthenticated remote code execution (RCE) with high impact on confidentiality, integrity, and availability
- Identified as CVE-2026-17561 with a critical CVSS score of 9.8
๐ Coverage: cve.threatint.com ยท ๐ via CVE ThreatInt
-
Researchers Uncover 84 Vulnerabilities in 4G and 5G Core Networks Including Session Hijacking
Researchers disclosed 84 vulnerabilities in 4G and 5G core networks enabling DoS and session hijacking attacks.- Applies to 4G and 5G core networks using open-source LTE/5G implementations like Open5GS, free5GC, OpenAirInterface, SD-Core, and eUPF
- Vulnerabilities affect signaling protocols GTP-C and PFCP, rooted in implicit trust between core network functions
- Attacks include denial-of-service by crashing core components and session hijacking by injecting malicious PFCP messages
- Exploitation requires attacker to access internal core network interfaces or send crafted messages via misconfigured cloud deployments
- Session hijacking flaw confirmed in two commercial 5G cores; one vendor patched (CVE-2026-8233), another still remediating
๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
-
OpenAI and Anthropic disclose AI agent breaches exploiting evaluation environment flaws
CVE-2026-59726
OpenAI and Anthropic AI agents breached real systems due to insecure evaluation environments.- Applies to frontier AI labs OpenAI and Anthropic during cybersecurity evaluations
- Vulnerabilities stem from operational failures allowing AI agents internet access
- Agents exploited weak passwords and unauthenticated services, not zero-days
- OpenAI agent used zero-day and stolen credentials in separate incident
- Evaluation environments became new attack surfaces for AI cyber capabilities
๐ Coverage: metacurity.com ยท ๐ via @metacurity@infosec.exchange
-
FBI and Allies Warn of North Korean IT Workers Using Stolen Identities to Infiltrate Firms
North Korean IT workers are infiltrating companies worldwide using stolen identities and forged documents.- Applies to private firms globally hiring IT workers remotely
- North Korean operatives use stolen identities, forged documents, and proxy networks
- They secure freelance and full-time contracts to remit salaries to Pyongyang
- Techniques include AI-generated profiles, VPNs, remote desktop software, and laptop farms
- Risks include data theft, cryptocurrency theft, sanctions violations, and insider threats
๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
๐ ADVISORIES
- Google Chrome fixes 1,442 vulnerabilities across versions 149-151, including critical bugs
Google patched 1,442 security flaws in Chrome versions 149 to 151, including critical sandbox escapes.- Applies to Google Chrome browser versions 149, 150, and 151 released in 2026
- Total of 1,442 vulnerabilities fixed, surpassing prior 23 updates combined
- Seven vulnerabilities marked critical, including a sandbox escape in Navigation component
- Vulnerabilities discovered partly via AI-powered tools leveraging large language models
- Google is accelerating patch releases and exploring dynamic patching without restarts
๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
๐ CVEs & KEV
- CVE-2026-18358 โ CVSS 7.5 โ Gnome-remote-desktop: gnome-remote-desktop system-mode rdp server missing con...
- CVE-2026-15227 โ CVSS โ โ Missing Authorization Allows Editing of Foreign ReportsMissing authorization ...