hacker-news · Crawled Sep 5, 2026

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

6 IoCs
Read original article ↗

AI Summary

In August 2026, unidentified threat actors exploited a critical vulnerability, CVE-2026-63077, in JetBrains' TeamCity server to breach the Cadence cloud service environment. The attackers gained access to a 2024 backup of the Cadence server, extracting sensitive data including personal information, source code, and AWS IAM credentials belonging to JetBrains employees and users. JetBrains confirmed unauthorized access between August 8 and 24, 2026, and urged all Cadence users to immediately rotate credentials and treat all executions as potentially compromised due to exposure of secrets and configurations.

AI-extracted · verify before operational use

Indicators of Compromise 6 extracted

Type Value Detail
IP 150[.]109[.]230[.]104 Details →
IP 43[.]153[.]227[.]206 Details →
IP 62[.]210[.]127[.]48 Details →
IP 210[.]247[.]242[.]190 Details →
IP 15[.]235[.]225[.]205 Details →
IP 152[.]233[.]30[.]18 Details →