Threats Tagged 'cve-2024-27198'
View all threats tagged with 'cve-2024-27198'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2024-27198'
Click on any threat for detailed analysis and mitigation recommendations
0 Earth Lamia, an APT threat actor, has been targeting organizations in Brazil, India, and Southeast Asia since 2023. The group exploits web application vulnerabilities, particularly SQL injection, to gain access to targeted systems. They have developed custom tools like PULSEPACK backdoor and BypassBoss for privilege escalation. Earth Lamia's targets have shifted over time, initially focusing on financial services, then logistics and online retail, and recently IT companies, universities, and government organizations. The group employs various techniques including DLL sideloading, use of legitimate binaries, and development of modular backdoors. Earth Lamia's activities have been linked to other reported campaigns, suggesting a complex and evolving threat landscape. Join the discussion | AlienVault OTX General | 05/27/2025, 10:35:05 UTC Added: 05/27/2025, 13:28:23 UTC |
0 CVE-2024-27198 is a critical authentication bypass vulnerability in JetBrains TeamCity versions prior to 2023.11.4. This flaw, classified under CWE-288, allows unauthenticated attackers to perform administrative actions without proper authorization. The vulnerability has a CVSS v3.1 score of 9.8, indicating a severe risk with network attack vector, no required privileges or user interaction, and full impact on confidentiality, integrity, and availability. Although no known exploits are currently reported in the wild, the potential for abuse is significant given TeamCity’s role in continuous integration and deployment pipelines. Organizations using affected TeamCity versions should prioritize patching to prevent unauthorized access and potential compromise of build environments. Countries with substantial use of JetBrains TeamCity and strong software development sectors are at higher risk. Join the discussion | CVE Database V5 | 03/04/2024, 17:21:39 UTC Added: 10/21/2025, 19:06:26 UTC |
Showing 1 to 2 of 2 results