Risky Bulletin Newsletter
October 04, 2023
Risky Biz News: Ransomware gangs hit TeamCity and WS_FTP servers
Presented by

News Editor
Ransomware groups are exploiting recently disclosed vulnerabilities in TeamCity and WS_FTP servers to breach corporate networks and ransom organizations.
The attacks are exploiting CVE-2023-42793 and CVE-2023-40044.
The first is an authentication bypass and RCE vulnerability that can allow threat actors to take full control of JetBrains TeamCity CI/CD servers. Once on the development pipeline, threat actors can pivot to other resources on a company's internal or cloud network, from where ransomware gangs can do extensive damage.