Since September 2023, Russian Foreign Intelligence Service-affiliated cyber actors, the Dukes, CozyBear, and NOBELIUM/Midnight Blizzard) have been targeting servers hosting JetBrains TeamCity software that ultimately enabled them to bypass authorization and conduct arbitrary code execution on the compromised server.
The joint CSA provides information on the SVR's most recent compromise, actionable indicators of compromise, and SIGMA and YARA rules.
The authoring agencies encourage network defenders and organizations review the joint CSA for recommended mitigations and rules.
For more guidance to protect against the most common and impactful threats, visit CISA's Cross-Sector Cybersecurity Performance Goals.
This product is provided subject to this Notification and this Privacy & Use policy.
This Cyber News was published on www.cisa.gov. Publication date: Wed, 13 Dec 2023 18:43:12 +0000