Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
- ID
- 21807
- Status
- summarized
- Published
- 06 Sep 2026, 12:52 AM
- Fetched
- 06 Sep 2026, 1:09 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.5
- Created
- 06 Sep 2026, 1:10 AM
- Tags
- Audience
- developersai-ml-learnersvibe_coders
What happened
Attackers exploited CVE-2026-63077 (CVSS 9.8), a critical TeamCity deserialization flaw already on CISA's KEV catalog since August 5, 2026, to breach JetBrains' own Cadence environment. JetBrains discovered the breach on August 23, 2026 and confirmed attackers accessed a 2024 Cadence server backup plus storage containing current users' email addresses, project source code, and credentials. JetBrains is instructing all Cadence users to immediately revoke and rotate every credential or secret used in Cadence executions and to treat all past executions, inputs, and outputs as potentially untrusted.
Why it matters
If you or your team uses JetBrains Cadence (the PyCharm cloud GPU plugin for ML workloads), you must rotate all credentials and secrets now — AWS keys, API tokens, anything stored in or passed to Cadence executions — because JetBrains confirms they may be compromised. If you run TeamCity anywhere in your CI/CD pipeline, patch CVE-2026-63077 immediately; it's under active in-the-wild exploitation and allows unauthenticated remote code execution.
Discussion angle
How many teams in this community actually rotate secrets stored in IDE plugins or CI tools after a vendor breach — and what's a practical rotation workflow when you don't know exactly which credentials were exposed?