Threat Intelligence

JetBrains Cadence Breach: Attackers Exploited Unpatched TeamCity to Steal AWS Credentials

The Hacker News · 6 Sept 2026
Key Takeaway If your business uses JetBrains Cadence or hosts TeamCity servers, patch immediately and rotate any credentials that may have touched these systems, even if you have not been directly notified.

JetBrains has disclosed that unidentified attackers breached its Cadence cloud computing service by exploiting CVE-2026-63077, a critical deserialization vulnerability in TeamCity rated 9.8 out of 10 for severity. The flaw allows an unauthenticated attacker with access to a TeamCity server to bypass authentication and run arbitrary commands with the server's privileges. Cadence is a JetBrains hosted service that integrates with PyCharm to let developers run machine learning and heavy workloads on cloud GPUs directly from their IDE.

JetBrains discovered the exploitation on August 23, 2026, though the vulnerability had already been added to CISA's Known Exploited Vulnerabilities catalog weeks earlier, on August 5. Investigators found the attackers accessed a Cadence server backup from 2024 and may have reached storage containing current users' email addresses, project source code, and credentials, including AWS credentials.

JetBrains is directly contacting affected users but has warned that all Cadence customers should treat their executions, inputs, and outputs as potentially untrusted. The company stressed that any credentials or secrets stored in Cadence, contained in the compromised backup, or exposed to executions on the affected server should now be considered compromised.

Key Takeaway: If your business uses JetBrains Cadence or hosts TeamCity servers, patch immediately and rotate any credentials that may have touched these systems, even if you have not been directly notified.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.