CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
A deserialization flaw in on-premise JetBrains TeamCity servers is being actively exploited, letting unauthenticated attackers bypass authentication via the agent polling protocol and run arbitrary commands with the privileges of the TeamCity server process. Successful attacks can expose stored credentials and configurations and compromise the integrity of downstream CI/CD build pipelines. Federal civilian agencies were given until August 8 to patch under CISA’s binding directive, and a follow-up technical analysis published August 7 detailed how a permissive deserialization allowlist in vulnerable versions enabled the bug.
CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild
An authentication bypass in the widely deployed N-central remote monitoring and management platform has been under active exploitation since August 1, allowing unauthenticated attackers to seize administrative control of vulnerable servers. The flaw emerged from an incomplete fix for an earlier bypass issue, and attackers who exploited it used the platform’s built-in remote access tooling plus a Cloudflare Tunnel to maintain persistent access to managed customer endpoints. Because N-central operates with broad privileges across the environments it manages, a compromised server gives attackers an efficient path into downstream client networks, and the vendor is urging affected organizations to patch outside normal cycles and hunt for indicators of compromise.
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
A technical breakdown of the DeadLock ransomware operation shows its pre-encryption routine is built to cripple both prevention and recovery before files are ever touched. The malware uses a PowerShell script to bypass User Account Control and disable Windows Defender, terminates backup and database services, deletes volume shadow copies, and clears Security, System, Application and PowerShell event logs by walking the Windows registry and stripping channel permissions. The ransomware pairs this scorched-earth approach with double extortion, exfiltrating corporate data before encrypting systems and threatening to publish it if victims don’t pay.
Red Hat Kubernetes Flaw Allows Attackers to Escalate Privileges to Cluster-Admin
A privilege-escalation vulnerability rated 9.9 out of 10 in Red Hat Advanced Cluster Management for Kubernetes lets a low-privileged user with only namespace-scoped edit rights seize full cluster-admin control of a hub cluster. The bug is a confused-deputy issue in the application-subscription workflow: a user can point a Channel object at an attacker-controlled Helm repository, then deploy a chart containing a ClusterRoleBinding that grants an attacker-controlled service account cluster-admin access, since the controller never checks whether the requester actually holds subscription-admin rights. Red Hat has not yet shipped a fix that meets its product-security bar, so it’s advising teams to audit who holds edit rights in ACM hub namespaces and watch for unexpected cluster-scoped objects showing up through subscriptions.
U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang
CISA, the FBI, NSA, Secret Service and South Korea’s National Police Agency issued a joint advisory warning about Gunra, a ransomware-as-a-service operation built on leaked Conti code that has hit academia, finance, healthcare, manufacturing, government and critical infrastructure across Africa, the Americas, Asia-Pacific, Europe and the Middle East. The group has expanded by recruiting penetration testers and ethical hackers as initial-access brokers in exchange for a cut of ransom profits, typically breaking in through known vulnerabilities in internet-facing VPNs and firewalls, and researchers have also flagged technical overlap between Gunra’s tooling and infrastructure linked to North Korea’s Lazarus Group.