- Critical authentication bypass vulnerability in JetBrains TeamCity
ThreatNoir Afternoon Brief — September 24
Afternoon Review in IT Security — September 24, 2026
The cybersecurity landscape continues to evolve rapidly as threat actors adapt their tactics and vendors race to patch critical vulnerabilities. This afternoon's review covers emerging ransomware exploitation campaigns, sophisticated social engineering techniques gaining traction across enterprise networks, and critical infrastructure security guidance updates from federal agencies.
CISA: Ransomware gangs now exploiting critical TeamCity flaw
The U.S. Cybersecurity and Infrastructure Security Agency has issued a warning to federal agencies regarding ransomware gangs actively exploiting a critical JetBrains TeamCity vulnerability that was originally patched in July. The vulnerability, tracked as CVE-2026-63077, represents an authentication bypass that could allow attackers to gain unauthorized access to TeamCity installations. Source: CISA: Ransomware gangs now exploiting critical TeamCity flaw
The timing of this exploitation campaign highlights the persistent risk posed by unpatched systems in production environments. Organizations that have delayed applying the July patch remain vulnerable to active ransomware operations, making immediate remediation a critical priority for federal agencies and private sector entities managing TeamCity infrastructure.
17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360
A comprehensive threat report has exposed the evolution of ClickFix from an emerging technique in late 2023 to a subscription-based malware delivery service with state-sponsored operators. The analysis of 17,000 malicious URLs demonstrates how ClickFix has become the most prevalent attack vector for initial enterprise network compromise, operating without requiring exploits, attachments, or files on disk. Source: 17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360
The sophistication of ClickFix operations lies in their ability to weaponize trusted website interfaces through social engineering, rendering traditional domain-blocking defenses ineffective. The report indicates that blocking malicious domains alone is no longer a viable defense strategy, requiring organizations to implement behavioral detection and user awareness training to combat this evolving threat.
OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators
NIST has released Revision 4 of its operational technology security guide for public comment, with the feedback period extending until November 30, 2026. Concurrently, CISA and the FBI have issued guidance addressing security concerns related to third-party industrial control systems integrators and their access to critical infrastructure networks. Source: OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators
The updated guidance reflects growing concerns about supply chain risks in operational technology environments, where third-party integrators maintain elevated access privileges to industrial systems. Organizations managing critical infrastructure should review the draft NIST guidance and the federal agency advisories to strengthen their OT security posture and vendor management practices.
SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted
SolarWinds has released patches addressing critical remote code execution vulnerabilities in its Observability Self-Hosted product, identified as CVE-2026-28324 and CVE-2026-28325. Both vulnerabilities can be exploited without requiring authentication, presenting an immediate risk to organizations running affected versions of the software. Source: SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted
The unauthenticated nature of these remote code execution flaws elevates their severity significantly, as attackers can compromise systems without valid credentials. Organizations deploying SolarWinds Observability Self-Hosted should prioritize patching efforts immediately to prevent potential unauthorized access and data exfiltration from their monitoring infrastructure.
Today's threat landscape demonstrates the continued importance of timely patch management, vendor security assessment, and comprehensive user awareness programs. Organizations must balance rapid vulnerability remediation with careful testing to ensure operational continuity while defending against increasingly sophisticated attack campaigns.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- User Execution: Malicious Copy and Paste
- Critical RCE vulnerability in SolarWinds Observability Self-Hosted
- Critical RCE vulnerability in SolarWinds Observability Self-Hosted
- RCE vulnerability in SolarWinds Access Rights Manager