appsec.fyi · Sources

cyberdaily.au

5 curated AppSec resources from cyberdaily.au across 2 topics on appsec.fyi.

cyberdaily.au

Resources curated from this publisher and indexed across appsec.fyi topic pages. Last item added: 2026-07-30.

Date Added Resource Excerpt
2026-07-30 2026Update now! JetBrains warns of Critical RCE vulnerability in its TeamCity On-Premises platformRCEWriteup on CVE-2026-63077, a critical RCE vulnerability in JetBrains TeamCity On-Premises with a CVSS score of 9.8. This vulnerability allows unauthenticated attackers to bypass authentication and execute arbitrary OS commands. All TeamCity On-Premises versions are affected. Patches are available in versions 2025.11.7 and 2026.1.3, with a security patch plug-in for versions 2017.1 and later. Rapid7 advises urgent updates and restricting network access to TeamCity servers. The vulnerability was reported by Antoni Tremblay.
2026-07-24 2026SANDWORM_MODE: Understanding the first malware built to target AI coding assistantsSupply ChainAnalysis of SANDWORM_MODE, a sophisticated multi-stage worm distributed via malicious npm packages, details the first malware specifically designed to target AI coding assistants. This software supply chain attack, identified by Socket.dev and analyzed by CrowdStrike, steals credentials and API tokens, then tampers with AI tools by installing rogue servers that expose sensitive data. SANDWORM_MODE spreads through compromised repositories and source code platforms, making its actions difficult to distinguish from normal developer activity and highlighting the limitations of traditional endpoint monitoring in AI-driven development environments.
2026-07-20 2026Patch now! Researchers disclose WordPress Core remote code execution bug; exploitation under wayRCELibrary providing WordPress core security mitigation strategies against the unauthenticated RCE vulnerability, wp2shell. This vulnerability impacts WordPress versions 6.9.0-6.9.4 and 7.0.0-7.0.1. Recommended actions include updating to WordPress 7.0.2 or 6.9.5, blocking anonymous REST API access via plugins, or configuring a WAF to block specific paths. Exploitation is already underway, with proof-of-concept exploits circulating rapidly.
2026-05-18 2026US cyber agency warns of active exploitation of Microsoft Exchange Server spoofing vulnerabilityRCECatalog entry for CVE-2026-42897, a Microsoft Exchange Server spoofing vulnerability allowing arbitrary JavaScript execution in Outlook Web Access. Exploitable via specially crafted emails, this cross-site scripting flaw has a CVSS score of 8.1 and is actively being exploited. Microsoft offers a temporary mitigation and is developing a permanent fix.
2026-04-08 2026Your developers work for cyber gangsSupply ChainLibrary for securing open-source dependencies, addressing risks highlighted by March 2026 supply chain attacks. These incidents included credential theft via compromised scanners like Aqua Security's Trivy, invisible malware injection using Unicode payloads by GlassWorm, and a North Korean state actor hijacking the popular axios npm package. The library also covers the challenges posed by blockchain-based command-and-control infrastructure, making traditional takedown methods ineffective.