khalidabuhakmeh, to random
@khalidabuhakmeh@mastodon.social avatar

Pipelines looks really cool for folks who want to run CI/CD locally.

https://www.youtube.com/watch?v=2do8Mby92LI

michabbb, to cochlearimplants German
@michabbb@vivaldi.net avatar

Enter the CI/CD flow Beta

Pipelines is a new approach to / that offers blazing fast pipelines to optimize your development flow.

https://www.jetbrains.com/teamcity/pipelines/

image/png

Rjdlandscapes, to random

Sigh 2 days of screwing around with to do our mobile builds (iOS and android) finally managed to get the right magic sequence working..

Like making a jigsaw with a blindfold on.

simontsui, to random

Yet another JetBrains TeamCity On-Prem vulnerability: CVE-2024-23917 (9.8 critical)

If abused, the flaw may enable an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and gain administrative control of that TeamCity server.

๐Ÿ”— https://blog.jetbrains.com/teamcity/2024/02/critical-security-issue-affecting-teamcity-on-premises-cve-2024-23917/

simontsui,

Why you should care about CVE-2024-23917:
Russian Foreign Intelligence Service (SVR) exploited a similar JetBrains TeamCity authentication bypass vulnerability CVE-2023-42793 (9.8 critical) worldwide, as reported in a CISA cybersecurity advisory dated 13 December 2023, less than 2 months ago.

securityaffairs, to Russia Italian
0x58, to Cybersecurity

๐Ÿ“จ Latest issue of my curated and list of resources for week /2023 is out! It includes the following and much more:

โž ๐Ÿ”“ ๐Ÿ‘€ Tracking Unauthorized Access to 's Support System
โž ๐Ÿ”“ ๐Ÿ‡ฏ๐Ÿ‡ต discloses impacting customers in 149 countries
โž ๐Ÿ”“ ๐Ÿงฌ Hacker leaks millions more user records on forum
โž ๐Ÿ”“ ๐Ÿ‡จ๐Ÿ‡ณ D-Link confirms data breach after employee attack
โž ๐Ÿ”“ ๐Ÿ’ฐ Fined $13.5 Million Over 2017 Data Breach
โž ๐Ÿ‡บ๐Ÿ‡ฆ ๐Ÿงน Ukrainian activists hack Trigona gang, wipe servers
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ‡ฐ๐Ÿ‡ต FBI: Thousands of Remote IT Workers Sent Wages to to Help Fund Weapons Program
โž ๐Ÿ‡ฎ๐Ÿ‡ณ โ˜๏ธ targets , tech support in nationwide crackdown
โž ๐Ÿ‡ต๐Ÿ‡ธ ๐Ÿ‡ฎ๐Ÿ‡ท -linked app offers window into cyber infrastructure, possible links to Iran
โž ๐Ÿ‘ฎ๐Ÿปโ€โ™‚๏ธ ๐Ÿฅท๐Ÿป Police seize leak site
โž ๐Ÿ‡ฐ๐Ÿ‡ต North Korean Hackers Exploiting Recent Vulnerability
โž ๐Ÿ‡จ๐Ÿ‡ณ ๐Ÿ‡ท๐Ÿ‡บ replaces as top
โž ๐Ÿ‡บ๐Ÿ‡ฆ ๐Ÿ“ก CERT-UA Reports: 11 Ukrainian Telecom Providers Hit by Cyberattacks
โž ๐Ÿ‡ซ๐Ÿ‡ท ๐Ÿ‡ช๐Ÿ‡ธ frees the two biggest Spanish hackers
โž ๐Ÿ‡บ๐Ÿ‡ธ โš“๏ธ Ex-Navy IT head gets 5 years for selling peopleโ€™s data on
โž ๐Ÿ‡จ๐Ÿ‡ญ ๐Ÿ—ณ๏ธ โ€™s e-voting system has predictable implementation blunder
โž ๐Ÿ”“ ๐Ÿญ Critical Vulnerabilities Expose โ€‹โ€‹ HMIs to Attacks
โž ๐Ÿ”“ ๐Ÿญ Industrial Router Possibly Exploited in Attacks
โž ๐Ÿฆ  ๐Ÿ‡ป๐Ÿ‡ณ Fake job offers on push malware
โž ๐Ÿฆ  Google-hosted leads to fake site that looks genuine
โž ๐Ÿฆ  ๐Ÿ’ฌ still a hotbed of activity โ€” Now APTs join the fun
โž ๐Ÿฆ  ๐Ÿ•ต๐Ÿปโ€โ™‚๏ธ SpyNote: Beware of This Android that Records Audio and Phone Calls
โž ๐Ÿ›๏ธ ๐Ÿฆ  will now scan sideloaded apps for malware at install time
โž ๐Ÿ’ฌ ๐Ÿ” on the way, but as usual, for Android first
โž ๐Ÿ‡ท๐Ÿ‡บ ๐Ÿ—‚๏ธ Pro-Russian Hackers Exploiting Recent Vulnerability in New Campaign
โž ๐Ÿ—“๏ธ โŒ Signal Pours Cold Water on Zero-Day Exploit Rumors
โž ๐Ÿ”“ ๐Ÿ’ฅ warns of new XE actively exploited in attacks

๐Ÿ“š This week's recommended reading is: "RTFM: Red Team Field Manual v2" by Ben Clark and Nicholas Downer

Subscribe to the newsletter to have it piping hot in your inbox every week-end โฌ‡๏ธ

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-422023

khalidabuhakmeh, to dotnet
@khalidabuhakmeh@mastodon.social avatar

Iโ€™m hosting a webinar today with Jeffrey Palermo about CI/CD pipelines for developers.

Feel free to join us and bring questions.

Boosts are appreciated.

https://www.youtube.com/watch?v=-dltQHFZiNg

YourAnonRiots, to infosec Japanese

UPDATE: Active exploitation of a critical bug in detected. groups and others are now weaponizing this for remote code execution.

https://thehackernews.com/2023/09/critical-jetbrains-teamcity-flaw-could.html#active-exploitation-of-jetbrains-teamcity-flaw-detected

Freemind, to Cybersecurity
@Freemind@mastodon.online avatar

Successful exploitation of the vulnerability could also allow threat actors to access the build pipelines and inject arbitrary code, leading to an integrity breach and supply chain compromise.

https://cybersec84.wordpress.com/2023/09/26/jetbrains-teamcity-vulnerability-unpatched-servers-at-risk/

punker76, to dotnet German

What is the best alternative for command line tool from @jetbrains ?

  • All
  • Subscribed
  • Moderated
  • Favorites
  • โ€ข
  • provamag3
  • thenastyranch
  • magazineikmin
  • ethstaker
  • InstantRegret
  • tacticalgear
  • rosin
  • love
  • Youngstown
  • slotface
  • ngwrru68w68
  • kavyap
  • cubers
  • DreamBathrooms
  • megavids
  • mdbf
  • modclub
  • GTA5RPClips
  • normalnudes
  • khanakhh
  • everett
  • cisconetworking
  • osvaldo12
  • anitta
  • Leos
  • Durango
  • tester
  • JUstTest
  • All magazines