<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: BeyondMachines</title>
    <description>The latest articles on DEV Community by BeyondMachines (@bsp_beyondmachines).</description>
    <link>https://dev.to/bsp_beyondmachines</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F2445503%2F3faf5e64-542b-44d9-9bb9-e5bdaa993b59.png</url>
      <title>DEV Community: BeyondMachines</title>
      <link>https://dev.to/bsp_beyondmachines</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/bsp_beyondmachines"/>
    <language>en</language>
    <item>
      <title>JetBrains Fixes Critical TeamCity Authentication Bypass Allowing Remote Code Execution</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Tue, 28 Jul 2026 20:01:50 +0000</pubDate>
      <link>https://dev.to/beyondmachines/jetbrains-fixes-critical-teamcity-authentication-bypass-allowing-remote-code-execution-3ajj</link>
      <guid>https://dev.to/beyondmachines/jetbrains-fixes-critical-teamcity-authentication-bypass-allowing-remote-code-execution-3ajj</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;JetBrains patched a critical authentication bypass (CVE-2026-63077) in TeamCity On-Premises that allows unauthenticated remote code execution. The flaw affects all on-premises versions and could lead to a full takeover of CI/CD pipelines.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;If you run TeamCity On-Premises, urgently update to version 2025.11.7 or 2026.1.3 to patch CVE-2026-63077. All on-premises versions are vulnerable to a full server takeover. TeamCity Cloud is already patched and needs no action. If you can't update right away, install the security patch plugin (for versions 2017.1 and later) and restrict access to your TeamCity server to trusted internal networks or a VPN.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/jetbrains-fixes-critical-teamcity-authentication-bypass-allowing-remote-code-execution-c-x-w-3-z/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>GitLab Remote Code Execution Chain Exploits Long-Standing Memory Flaws in Oj Parser</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Tue, 28 Jul 2026 10:01:42 +0000</pubDate>
      <link>https://dev.to/beyondmachines/gitlab-remote-code-execution-chain-exploits-long-standing-memory-flaws-in-oj-parser-112c</link>
      <guid>https://dev.to/beyondmachines/gitlab-remote-code-execution-chain-exploits-long-standing-memory-flaws-in-oj-parser-112c</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;GitLab patched a critical remote code execution chain involving two memory corruption flaws in the Oj Ruby JSON parser that allow authenticated users to take over servers via malicious Jupyter notebook diffs.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;If you run self-managed GitLab, upgrade immediately to version 18.10.8, 18.11.5, or 19.0.2. There's a working exploit published and any user who can push code to a project can take over the server. If you're on version 15.2 through 18.9, those are no longer supported and won't get a patch, so you must move to a supported release to be protected.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/gitlab-remote-code-execution-chain-exploits-long-standing-memory-flaws-in-oj-parser-q-z-g-i-b/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Arista Patches Critical VeloCloud Orchestrator Zero-Day Under Active Attack</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Tue, 28 Jul 2026 09:01:43 +0000</pubDate>
      <link>https://dev.to/beyondmachines/arista-patches-critical-velocloud-orchestrator-zero-day-under-active-attack-47lb</link>
      <guid>https://dev.to/beyondmachines/arista-patches-critical-velocloud-orchestrator-zero-day-under-active-attack-47lb</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Arista Networks released an emergency advisory for a CVSS 10.0 OS command injection vulnerability in VeloCloud Orchestrator On-Prem that is currently being exploited in the wild. The flaw allows unauthenticated attackers to gain full control over the orchestrator and all managed SD-WAN edge devices.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;Make sure all VeloCloud Orchestrator On-Prem devices are isolated from the internet and accessible only from trusted administrative networks. Then immediately upgrade to a fixed release (5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1) and block the known malicious IPs (8.19.75.217, 206.72.242.124, 206.72.242.162) at your firewall. After patching rotate all credentials and certificates so attackers can't reuse any potentially stolen data.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/arista-patches-critical-velocloud-orchestrator-zero-day-under-active-attack-x-b-e-7-y/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>CISA Warns of Active Exploitation in Fortinet FortiOS SSL-VPN Patch Bypass</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Tue, 28 Jul 2026 08:01:42 +0000</pubDate>
      <link>https://dev.to/beyondmachines/cisa-warns-of-active-exploitation-in-fortinet-fortios-ssl-vpn-patch-bypass-4ll</link>
      <guid>https://dev.to/beyondmachines/cisa-warns-of-active-exploitation-in-fortinet-fortios-ssl-vpn-patch-bypass-4ll</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;CISA reports active explotation of  CVE-2025-68686, a flaw in Fortinet FortiOS that allows attackers to bypass security patches and maintain persistent access on compromised devices.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;If you use Fortinet devices, make sure they are isolated from the internet and accessible only from trusted networks. Then update FortiOS ASAP to version 7.6.2, 7.4.7, or later. This flaw is combined with others, so make sure all your Fortinet devices are up-to-date. And check your devices for indicators of compromise, this flaw allowed hackers to maintain access over patch cycles.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/cisa-warns-of-active-exploitation-in-fortinet-fortios-ssl-vpn-patch-bypass-h-6-5-r-8/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>State of (in)security - Week 30, 2026</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Mon, 27 Jul 2026 19:01:42 +0000</pubDate>
      <link>https://dev.to/beyondmachines/state-of-insecurity-week-30-2026-3doa</link>
      <guid>https://dev.to/beyondmachines/state-of-insecurity-week-30-2026-3doa</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;During week 30 of 2026, cybersecurity monitoring recorded 7 advisories and 28 incidents/breaches affecting roughly 80 million individuals. The largest breach is Suno exposing 55.3 million users and AI training source code. Malware/ransomware and unauthorized access are the leading causes of incidents and healthcare and IT/software as the most-targeted industries.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;Patch the actively exploited on-premises SharePoint (CVE-2026-50522), self-hosted ServiceNow, Fastjson 1.x Java apps, Oracle systems (July 2026 Critical Patch Update), and WordPress. Then update Firefox and Thunderbird and confirm your Adobe Acrobat Chrome extension is running version 26.5.2.3 or later.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/state-of-in-security-week-30-2026-w-0-e-b-i/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Whitfield Regional Hospital Discloses Data Breach Exposing Sensitive Patient Information</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Mon, 27 Jul 2026 18:01:43 +0000</pubDate>
      <link>https://dev.to/beyondmachines/whitfield-regional-hospital-discloses-data-breach-exposing-sensitive-patient-information-3k65</link>
      <guid>https://dev.to/beyondmachines/whitfield-regional-hospital-discloses-data-breach-exposing-sensitive-patient-information-3k65</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Whitfield Regional Hospital in Alabama disclosed a data breach involving unauthorized access to its network between May 15 and June 8, 2025. The incident exposed sensitive personal, financial, and medical information, including Social Security numbers and health insurance data. The hospital is offering affected individuals 12 months of complimentary credit monitoring and identity protection services through Experian.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/whitfield-regional-hospital-discloses-data-breach-j-x-x-5-7/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Wildwood Surgical Center Discloses Data Breach Exposing Patient and Medical Records</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Mon, 27 Jul 2026 17:01:43 +0000</pubDate>
      <link>https://dev.to/beyondmachines/wildwood-surgical-center-discloses-data-breach-exposing-patient-and-medical-records-16h1</link>
      <guid>https://dev.to/beyondmachines/wildwood-surgical-center-discloses-data-breach-exposing-patient-and-medical-records-16h1</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Wildwood Surgical Center disclosed a data breach from June 2025 that exposed the personal, medical, and financial information of an undisclosed number of patients. The facility detected the unauthorized access in 2025 but did not complete its data review and victim notification process until July 2026.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/wildwood-surgical-center-discloses-data-breach-exposing-patient-and-medical-records-i-2-w-x-z/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Michigan Surgical Center Reports Data Breach Following Ransomware Claims by The Gentlemen Group</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Mon, 27 Jul 2026 16:02:01 +0000</pubDate>
      <link>https://dev.to/beyondmachines/michigan-surgical-center-reports-data-breach-following-ransomware-claims-by-the-gentlemen-group-16i3</link>
      <guid>https://dev.to/beyondmachines/michigan-surgical-center-reports-data-breach-following-ransomware-claims-by-the-gentlemen-group-16i3</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Michigan Surgical Center LLC disclosed a data breach on July 17, 2026, following ransomware claims by "The Gentlemen" group. The center is offering 24 months of free credit monitoring to affected individuals while investigating the extent of the unauthorized access.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/michigan-surgical-center-reports-data-breach-following-ransomware-claims-by-the-gentlemen-group-0-w-a-j-3/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>MongoDB Patches 26 Vulnerabilities Including Critical Memory Corruption Flaw</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Mon, 27 Jul 2026 15:01:43 +0000</pubDate>
      <link>https://dev.to/beyondmachines/mongodb-patches-26-vulnerabilities-including-critical-memory-corruption-flaw-2o87</link>
      <guid>https://dev.to/beyondmachines/mongodb-patches-26-vulnerabilities-including-critical-memory-corruption-flaw-2o87</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;MongoDB released security updates to fix 26 vulnerabilities, including a critical memory corruption flaw (CVE-2026-13072) and multiple high-severity issues that allow unauthorized data access and service crashes.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;If you run self-hosted MongoDB, update your servers now to the latest patched version (7.0.39, 8.0.28, 8.2.12, 8.3.7, or 9.0.0-rc1). There's a critical flaw that could let attackers crash your database or run their own code. If you use MongoDB Atlas or another managed service, you're already covered and don't need to do anything.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/mongodb-patches-26-vulnerabilities-including-critical-memory-corruption-flaw-0-u-a-i-s/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Penobscot Valley Hospital Discloses Data Breach Impacting Patient PHI and Financial Records</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Mon, 27 Jul 2026 14:01:42 +0000</pubDate>
      <link>https://dev.to/beyondmachines/penobscot-valley-hospital-discloses-data-breach-impacting-patient-phi-and-financial-records-38j7</link>
      <guid>https://dev.to/beyondmachines/penobscot-valley-hospital-discloses-data-breach-impacting-patient-phi-and-financial-records-38j7</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Penobscot Valley Hospital in Maine suffered a data breach where attackers accessed files containing patient health information, Social Security numbers, and financial data. The hospital is offering identity monitoring services to affected individuals.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/penobscot-valley-hospital-discloses-data-breach-impacting-patient-phi-and-financial-records-5-e-1-c-m/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>TripleX Group Claims 1TB Data Breach of Bank of Baroda Customer Records</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Mon, 27 Jul 2026 12:01:42 +0000</pubDate>
      <link>https://dev.to/beyondmachines/triplex-group-claims-1tb-data-breach-of-bank-of-baroda-customer-records-15kj</link>
      <guid>https://dev.to/beyondmachines/triplex-group-claims-1tb-data-breach-of-bank-of-baroda-customer-records-15kj</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;The TripleX hacking group claims to have leaked 1TB of sensitive Bank of Baroda customer and internal data on the dark web. The bank has not yet confirmed the incident.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/triplex-group-claims-1tb-data-breach-of-bank-of-baroda-customer-records-c-g-b-z-z/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Thailand Securities Depository Discloses Investor Portal Data Breach</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Mon, 27 Jul 2026 11:01:42 +0000</pubDate>
      <link>https://dev.to/beyondmachines/thailand-securities-depository-discloses-investor-portal-data-breach-2p8h</link>
      <guid>https://dev.to/beyondmachines/thailand-securities-depository-discloses-investor-portal-data-breach-2p8h</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Thailand Securities Depository (TSD) disclosed a data breach on July 26, 2026, after detecting unauthorized access to users’ personal information through its Investor Portal. The company blocked access to the affected system and confirmed that the incident did not affect securities trading, financial information, or assets held in its custody.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/thailand-securities-depository-discloses-investor-portal-data-breach-8-b-3-1-3/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
  </channel>
</rss>
