Toggle light / dark theme

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution.

The vulnerability, assigned CVE-2026–63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already been updated. JetBrains has credited Antoni Tremblay with discovering and reporting the flaw on July 10, 2026.

“If exploited, this flaw may enable an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process,” JetBrains said.

Genesis chip may help AI with its memory problem

One of artificial intelligence’s most stubborn problems is enabling AI systems to accumulate new knowledge without losing what they previously learned. A team of researchers at the MATRIX AI Consortium at The University of Texas at San Antonio may have solved this issue with Genesis, a spiking neuromorphic accelerator chip that would enable on-device continual learning throughout its operational lifetime.

Imagine a security drone trained to patrol a dense forest to spot signs of wildfire. After months of honing its ability to identify smoke among pine trees, the drone is reassigned to a coastal region to watch for floods. The moment the drone learns to interpret these new types of images, it might completely lose its ability to detect a forest fire. In the world of artificial intelligence, this phenomenon is known as “catastrophic forgetting,” and it remains one of the biggest hurdles to creating truly intelligent, autonomous agents.

New Certighost PoC exploit lets attackers hijack Windows domains

A proof-of-concept exploit for “Certighost,” a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain.

Tracked as CVE-2026–54121, the vulnerability was fixed by Microsoft as part of the July 2026 Patch Tuesday security updates.

“An authenticated attacker could manipulate attributes associated with a machine account and obtain a certificate from Active Directory Certificate Services that allows authentication as that machine via PKINIT,” Microsoft explained.

The Genesis Mission

The Mission is a national initiative led by the Department of Energy and its 17 national laboratories to build the world’s most powerful scientific platform to accelerate discovery science, strengthen national security, and drive energy innovation. It does so by enabling AI-driven, exascale-powered advances that enhance America’s energy innovation, global competitiveness, and security.

By connecting computing, data, and experimental facilities into a unified system, accelerates discovery and shortens the path from research to real-world impact, strengthening U.S. leadership in energy, security, and advanced technology.

Materials surrounding a fusion reaction can dramatically increase how often it occurs

Fusion at high temperatures powers the sun and, if harnessed, could provide a potential source of energy here on Earth. But controlling fusion reactions has other benefits. The process also generates subatomic particles called neutrons that are used in a range of applications spanning medicine, research and national security.

Scientists at the University of California, Davis, and the Department of Energy’s Lawrence Berkeley National Laboratory (Berkeley Lab) have found that the materials surrounding a fusion reaction can dramatically increase how often it occurs, particularly at low energies where fusion is rare. Their study is published in Nature Communications. The study’s first author is Micah Karahadian, a doctoral candidate in Munday’s lab at UC Davis.

Their approach establishes a way to study and engineer nuclear reactions within solid materials, opening a new field of “materials-driven fusion.” Instead of designing materials just to survive the harsh conditions of fusion, researchers might be able to design materials that boost the reaction under specific conditions, similar to the way catalysts speed up chemical processes.

Kimi K3 Agents Found Redis ZeroDays and Built RCE Exploit, Researchers Say

Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0.

All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis says the underlying memory flaws may lead to remote code execution.

Redis 6.2.23, 7.2.15, and 7.4.10 fix the Streams shared-NACK use-after-free; Redis 8.2.8, 8.4.5, and 8.6.5 fix both the Streams issue and the RedisBloom and TDigest out-of-bounds writes; Redis 8.8.1 fixes the RedisBloom and TDigest loaders, while the Streams guard was already present in Redis 8.8.0.

A petavoxel fragment of human cerebral cortex reconstructed at nanoscale resolution

From the article:

“In a 2024 Science study, researchers performed a high-resolution EM reconstruction of the ultrastructure of a cubic millimeter of human temporal cortex. According to the authors, the reconstruction contains roughly 57,000 cells, about 230 millimeters of blood vessels, and nearly 150 million synapses, comprising 1,400 terabytes of data.”


This website uses a security service to protect against malicious bots. This page is displayed while the website verifies you are not a bot.

/* */