The North Korean threat actors Lazarus and its subgroup Andariel are actively exploiting the CVE-2023-42793 vulnerability, which is an authentication bypass vulnerability, after successful exploitation, an attacker can perform a remote code execution attack and gain administrative control of the TeamCity server. These groups are deploying backdoor through this vulnerability, and their activities are likely aimed at conducting software supply chain attacks.
Get through updates and upcoming events, and more directly in your inbox