khalidabuhakmeh, to random
@khalidabuhakmeh@mastodon.social avatar

Pipelines looks really cool for folks who want to run CI/CD locally.

https://www.youtube.com/watch?v=2do8Mby92LI

michabbb, to cochlearimplants German
@michabbb@vivaldi.net avatar

Enter the CI/CD flow Beta

Pipelines is a new approach to / that offers blazing fast pipelines to optimize your development flow.

https://www.jetbrains.com/teamcity/pipelines/

image/png

Rjdlandscapes, to random
@Rjdlandscapes@mastodon.nz avatar

Sigh 2 days of screwing around with to do our mobile builds (iOS and android) finally managed to get the right magic sequence working..

Like making a jigsaw with a blindfold on.

simontsui, to random

Yet another JetBrains TeamCity On-Prem vulnerability: CVE-2024-23917 (9.8 critical)

If abused, the flaw may enable an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and gain administrative control of that TeamCity server.

๐Ÿ”— https://blog.jetbrains.com/teamcity/2024/02/critical-security-issue-affecting-teamcity-on-premises-cve-2024-23917/

#JetBrains #TeamCity #vulnerability #CVE_2024_23917 #authenticationbypass

simontsui,

Why you should care about CVE-2024-23917:
Russian Foreign Intelligence Service (SVR) exploited a similar JetBrains TeamCity authentication bypass vulnerability CVE-2023-42793 (9.8 critical) worldwide, as reported in a CISA cybersecurity advisory dated 13 December 2023, less than 2 months ago.

securityaffairs, to Russia Italian
0x58, to Cybersecurity

๐Ÿ“จ Latest issue of my curated #cybersecurity and #infosec list of resources for week #42/2023 is out! It includes the following and much more:

โž ๐Ÿ”“ ๐Ÿ‘€ Tracking Unauthorized Access to #Okta's Support System
โž ๐Ÿ”“ ๐Ÿ‡ฏ๐Ÿ‡ต #Casio discloses #databreach impacting customers in 149 countries
โž ๐Ÿ”“ ๐Ÿงฌ Hacker leaks millions more #23andMe user records on #cybercrime forum
โž ๐Ÿ”“ ๐Ÿ‡จ๐Ÿ‡ณ D-Link confirms data breach after employee #phishing attack
โž ๐Ÿ”“ ๐Ÿ’ฐ #Equifax Fined $13.5 Million Over 2017 Data Breach
โž ๐Ÿ‡บ๐Ÿ‡ฆ ๐Ÿงน Ukrainian activists hack Trigona #ransomware gang, wipe servers
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ‡ฐ๐Ÿ‡ต FBI: Thousands of Remote IT Workers Sent Wages to #NorthKorea to Help Fund Weapons Program
โž ๐Ÿ‡ฎ๐Ÿ‡ณ โ˜๏ธ #India targets #Microsoft, #Amazon tech support #scammers in nationwide crackdown
โž ๐Ÿ‡ต๐Ÿ‡ธ ๐Ÿ‡ฎ๐Ÿ‡ท #Hamas-linked app offers window into cyber infrastructure, possible links to Iran
โž ๐Ÿ‘ฎ๐Ÿปโ€โ™‚๏ธ ๐Ÿฅท๐Ÿป Police seize #RagnarLocker leak site
โž ๐Ÿ‡ฐ๐Ÿ‡ต North Korean Hackers Exploiting Recent #TeamCity Vulnerability
โž ๐Ÿ‡จ๐Ÿ‡ณ ๐Ÿ‡ท๐Ÿ‡บ #China replaces #Russia as top #cyberthreat
โž ๐Ÿ‡บ๐Ÿ‡ฆ ๐Ÿ“ก CERT-UA Reports: 11 Ukrainian Telecom Providers Hit by Cyberattacks
โž ๐Ÿ‡ซ๐Ÿ‡ท ๐Ÿ‡ช๐Ÿ‡ธ #France frees the two biggest Spanish hackers
โž ๐Ÿ‡บ๐Ÿ‡ธ โš“๏ธ Ex-Navy IT head gets 5 years for selling peopleโ€™s data on #darkweb
โž ๐Ÿ‡จ๐Ÿ‡ญ ๐Ÿ—ณ๏ธ #Switzerlandโ€™s e-voting system has predictable implementation blunder
โž ๐Ÿ”“ ๐Ÿญ Critical Vulnerabilities Expose โ€‹โ€‹#Weintek HMIs to Attacks
โž ๐Ÿ”“ ๐Ÿญ #Milesight Industrial Router #Vulnerability Possibly Exploited in Attacks
โž ๐Ÿฆ  ๐Ÿ‡ป๐Ÿ‡ณ Fake #Corsair job offers on #LinkedIn push #DarkGate malware
โž ๐Ÿฆ  Google-hosted #malvertising leads to fake #Keepass site that looks genuine
โž ๐Ÿฆ  ๐Ÿ’ฌ #Discord still a hotbed of #malware activity โ€” Now APTs join the fun
โž ๐Ÿฆ  ๐Ÿ•ต๐Ÿปโ€โ™‚๏ธ SpyNote: Beware of This Android #Trojan that Records Audio and Phone Calls
โž ๐Ÿ›๏ธ ๐Ÿฆ  #Android will now scan sideloaded apps for malware at install time
โž ๐Ÿ’ฌ ๐Ÿ” #WhatsApp #passkeys on the way, but as usual, for Android first
โž ๐Ÿ‡ท๐Ÿ‡บ ๐Ÿ—‚๏ธ Pro-Russian Hackers Exploiting Recent #WinRAR Vulnerability in New Campaign
โž ๐Ÿ—“๏ธ โŒ Signal Pours Cold Water on Zero-Day Exploit Rumors
โž ๐Ÿ”“ ๐Ÿ’ฅ #Cisco warns of new #IOS XE #zeroday actively exploited in attacks

๐Ÿ“š This week's recommended reading is: "RTFM: Red Team Field Manual v2" by Ben Clark and Nicholas Downer

Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end โฌ‡๏ธ

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-422023

khalidabuhakmeh, to dotnet
@khalidabuhakmeh@mastodon.social avatar

Iโ€™m hosting a webinar today with Jeffrey Palermo about CI/CD pipelines for developers.

Feel free to join us and bring questions.

Boosts are appreciated.

https://www.youtube.com/watch?v=-dltQHFZiNg

YourAnonRiots, to infosec Japanese
@YourAnonRiots@mstdn.social avatar

UPDATE: Active exploitation of a critical bug in detected. groups and others are now weaponizing this for remote code execution.

https://thehackernews.com/2023/09/critical-jetbrains-teamcity-flaw-could.html#active-exploitation-of-jetbrains-teamcity-flaw-detected

Freemind, to Cybersecurity
@Freemind@mastodon.online avatar

Successful exploitation of the vulnerability could also allow threat actors to access the build pipelines and inject arbitrary code, leading to an integrity breach and supply chain compromise.

https://cybersec84.wordpress.com/2023/09/26/jetbrains-teamcity-vulnerability-unpatched-servers-at-risk/

punker76, to dotnet German

What is the best alternative for command line tool from @jetbrains ?

  • All
  • Subscribed
  • Moderated
  • Favorites
  • โ€ข
  • JUstTest
  • tacticalgear
  • rosin
  • Youngstown
  • mdbf
  • ngwrru68w68
  • slotface
  • khanakhh
  • ethstaker
  • everett
  • kavyap
  • thenastyranch
  • DreamBathrooms
  • magazineikmin
  • anitta
  • osvaldo12
  • InstantRegret
  • Durango
  • cisconetworking
  • modclub
  • cubers
  • GTA5RPClips
  • tester
  • normalnudes
  • Leos
  • provamag3
  • megavids
  • lostlight
  • All magazines