news.mlab.sh
Back to the feed
threat-intel

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

CriticalCVSS 9.8
Summary

JetBrains has revealed a security breach in its Cadence cloud computing service, exploited via a critical vulnerability (CVE-2026-63077) in TeamCity. Attackers gained unauthorized access to a 2024 server backup, extracting AWS credentials and personal data, including email addresses and source code. The vulnerability has been actively exploited, and JetBrains has taken offline the affected server, urging users to rotate all credentials and review connected systems for suspicious activity.

JetBrains has announced a significant security incident affecting its Cadence cloud computing service. The breach stemmed from the exploitation of CVE-2026-63077, a critical vulnerability in TeamCity, allowing attackers to compromise the Cadence server. The attackers accessed a server backup from 2024, which contained a wealth of sensitive information. JetBrains confirmed that this included AWS IAM users and associated credentials/secrets, as well as personal data such as usernames, real names, email addresses, last-login timestamps, and last accessed IP addresses. Furthermore, the attackers gained access to source code synchronized from PyCharm projects to the affected server, potentially exposing code, credentials, and configurations. The vulnerability has been actively exploited since August 23, 2026, and the affected server, api.cadence.jetbrains.com, has been taken offline. JetBrains has invalidated all access tokens used by the JetBrains Cadence plugin in PyCharm. Indicators of compromise include activity occurring from August 8, 2026, onwards, particularly authentication or activity using credentials previously stored in or accessible through Cadence, as well as unexpected repository clones or downloads, and unexpected commits to repositories. The potential consequences of this data exposure include an increased risk of targeted phishing, social engineering, impersonation, and other malicious communications using the affected names and email addresses. JetBrains is advising users to rotate all credentials, review connected systems for suspicious activity, and treat all executions as potentially untrusted. The company did not share details on why the server was not patched as part of its own vulnerability response efforts.

Read the full article at The Hacker News