Threat Brief — 2026-08-30 — Patch fatigue bites back
JetBrains confirmed that its own TeamCity server was left unpatched against a CISA KEV-listed vulnerability, resulting in theft of AWS keys, backups, and developer data. Separately, the Moobot botnet's source code, attack logs, and operator tooling were exposed through a misconfigured directory. A recurring theme this cycle: vendors and operators failing to apply fixes to their own infrastructure.
Top items
- JetBrains breached via its own unpatched TeamCity server. JetBrains admitted its TeamCity deployment was never patched against CVE-2026-63077KEV·R, a deserialization RCE that has been in CISA's Known Exploited Vulnerabilities catalog since early August. Attackers exploited the flaw to steal AWS credentials, backups, and developer data from JetBrains' own environment. This is a developing story first reported 2026-08-05 when CISA added CVE-2026-63077KEV·R to the KEV catalog; the new development is JetBrains' confirmation that it failed to patch its own infrastructure and suffered a breach. (src: securitylab-ru)
- Moobot botnet source code leaked via server misconfiguration. A misconfigured directory exposed the Moobot botnet's source code, attack logs, and operator tools to public access. Leaked botnet code lowers the barrier to entry for new operators and enables defenders to analyse botnet internals, but also risks forked or rebranded variants appearing in the wild. (src: securitylab-ru)
- PaperCut patch bypassed within a day. A chain of CVE-2026-81578KEV and CVE-2026-82078KEV allows unauthenticated remote code execution with high privileges against PaperCut NG/MF. Reports indicate the vendor's fix was bypassed almost immediately, continuing the pattern of rapid patch circumvention first reported 2026-08-27 by BleepingComputer. (src: securitylab-ru)
Themes
Patch-the-patcher problem. Both JetBrains and PaperCut illustrate a growing pattern: vendors and organisations struggle to apply critical fixes to their own systems, even when those fixes address actively exploited vulnerabilities. JetBrains' case is particularly notable because CVE-2026-63077KEV·R has been in CISA KEV for weeks, yet the vendor's own server remained vulnerable.
