A critical unauthenticated RCE in TeamCity, a major healthtech breach affecting thousands of US hospitals, a new Mirai-based botnet that resists cleanup, and nation-state activity against water and energy systems. Here's what mattered this week.
- Critical unauthenticated RCE in JetBrains TeamCity (CVSS 9.8) — patch now if you self-host
- Craneware, a billing vendor serving 2,000 US hospitals, confirms attackers stole employee, customer, and partner data
- Iran-linked actors reportedly targeting water and energy systems
- Russian state-linked actors exploiting misconfigured routers — new multi-nation advisory
- A new Mirai-based botnet ("Tengu") reboots IoT devices to survive cleanup attempts
- Two individuals prosecuted over the 2024 Transport for London cyberattack
- Critical, unauthenticated RCE in TeamCity — patch immediately
JetBrains disclosed CVE-2026-63077 (CVSS 9.8) , a critical unauthenticated remote code execution flaw affecting every version of TeamCity On-Premises, its widely used CI/CD server. The bug lives in TeamCity's agent polling protocol and stems from insecure deserialization of untrusted data — an attacker with plain HTTP(S) access to the server, no credentials required, can execute arbitrary OS commands with the privileges of the TeamCity server process.
Given TeamCity's role sitting at the center of build and deployment pipelines, a successful exploit could expose stored credentials, tamper with build artifacts, or compromise everything downstream in the pipeline — a serious software supply-chain risk. The flaw was privately reported on July 10 and patched in versions 2025.11.7 and 2026.1.3; TeamCity Cloud customers are already covered. JetBrains says it has no evidence of active exploitation yet, but given the unauthenticated nature of the bug and TeamCity's history of being targeted by state-sponsored groups and ransomware affiliates, expect that to change fast once technical details circulate further.
Action item: if you run TeamCity On-Premises, patch now or apply JetBrains' security patch plugin (supported back to 2017.1) — and restrict network access to trusted networks in the meantime.
Craneware breach hits a vendor behind 2,000 US hospitals
Edinburgh-based Craneware, whose billing and revenue-cycle software underpins claims and payment processing for roughly 2,000 US hospitals and nearly 10,000 clinics and pharmacies, disclosed a cyberattack in a July 20 filing to the London Stock Exchange. Attackers accessed and exfiltrated a significant volume of file names, and the company confirmed a portion of employee data along with customer and partner records was taken. Craneware says the incident has been contained, most of the accessed data appears non-sensitive, and there's no sign of ongoing compromise — but the full scope, including whether any patient health data was affected, is still under investigation. The company notified the UK's ICO and the FBI.
This is the latest in a run of healthcare vendor breaches this year — TriZetto, CareCloud, and Episource all disclosed similar incidents in recent months. The pattern is consistent: compromising one widely used software supplier gives attackers a foothold across dozens or hundreds of downstream healthcare organizations at once.
Takeaway: if your org relies on third-party healthcare billing or RCM software, this is a good week to review what data those vendors actually hold on your behalf, and confirm your incident-notification expectations are contractually spelled out.
Nation-state activity : critical infrastructure in the crosshairs
- Iran-linked actors are reportedly targeting water and energy systems — the latest in a string of critical infrastructure targeting from the region.
- Russian state-linked attackers are exploiting misconfigured routers, according to a new multi-nation security advisory issued this week.
- Researchers also flagged a shell company with alleged links to China's PLA, reportedly built to host network infrastructure that conceals state-sponsored cyber activity.
Three different nation-state threads, same theme: infrastructure and networking equipment remain the path of least resistance into sensitive environments.
New Mirai-based botnet resists cleanup by rebooting devices
A new IoT botnet dubbed "Tengu", built on the Mirai codebase, has a nasty trick: it reboots the compromised device whenever someone tries to kill the malicious process, making standard remediation attempts far less effective. Mirai-derived botnets remain one of the most persistent threats to poorly secured IoT and edge devices years after the original Mirai source leaked.
Legal: Transport for London hackers prosecuted
Two individuals, Thalha Jubair and Owen Flowers, were prosecuted this week over the 2024 cyberattack on Transport for London — a reminder that some of the higher-profile breaches from the past couple of years are now working their way through the courts.
Also worth a skim
- A flawed car alarm/telematics system reportedly left millions of vehicles exposed to remote hacking
- An AI-discovered Linux kernel zero-day enabling root privilege escalation
- "LegacyHive," a Windows exploitation chain reportedly bypassing security controls even on systems with July's patches installed
- Closing thought
Unlike last week, this week's headlines are a return to fairly familiar ground: an unauthenticated RCE in critical build infrastructure, another healthcare vendor breach, and nation-state actors leaning on the same old weak points — misconfigured routers and under-hardened critical infrastructure. Familiar doesn't mean low-stakes, though — the TeamCity flaw in particular deserves same-week patching if it's anywhere in your environment.
Sources: JetBrains, The Hacker News, Help Net Security, TechRepublic, Cybersecurity Dive, Cybernews, TechCrunch,
Top comments (0)