hacker-news · Crawled Sep 5, 2026
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
6 IoCs
Read original article ↗
AI Summary
In August 2026, unidentified threat actors exploited a critical vulnerability, CVE-2026-63077, in JetBrains' TeamCity server to breach the Cadence cloud service environment. The attackers gained access to a 2024 backup of the Cadence server, extracting sensitive data including personal information, source code, and AWS IAM credentials belonging to JetBrains employees and users. JetBrains confirmed unauthorized access between August 8 and 24, 2026, and urged all Cadence users to immediately rotate credentials and treat all executions as potentially compromised due to exposure of secrets and configurations.
AI-extracted · verify before operational use