IT-Security Insights

Blog

Articles for businesses and development teams, plus technical analysis covering penetration testing, secure development, vulnerability research and bug bounty.

These articles combine specific vulnerabilities, attack chains and practical experience with the question of what they mean for applications, development processes and security decisions.

Security for businesses and development teams

Article

XSS never dies

Why Cross-Site Scripting remains relevant despite modern frameworks and which assumptions frequently fail in practice.

Read

Security research and CVEs

CVE

CVE-2025-54531

Path Traversal while extracting plugins in JetBrains TeamCity before 2025.07 allowed Arbitrary File Write on Windows.

Read
CVE

CVE-2024-47950

Stored Cross-Site Scripting in the backup settings of JetBrains TeamCity before 2024.07.3.

Read
CVE

CVE-2024-47949

Path Traversal in JetBrains TeamCity before 2024.07.3 allowed a backup file to be written to an arbitrary path.

Read
CVE

CVE-2024-47948

Path Traversal in JetBrains TeamCity before 2024.07.3 allowed readable files to be disclosed through server backups.

Read
CVE

CVE-2024-56353

A backup file in JetBrains TeamCity before 2024.12 exposed credentials and session information.

Read

Bug bounty and community