importantSYS.SOURCE: The Hacker News• 2026-09-05T22:22:33+05:30
Unpatched TeamCity Vulnerability Leads to AWS Credential Theft in JetBrains Cadence Breach
Attackers exploited a critical unpatched TeamCity vulnerability (CVE-2026-63077) to breach JetBrains Cadence, extracting AWS credentials and compromising user data. JetBrains urges immediate credential rotation and system audits due to potential exposure of sensitive information.
JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment.
"Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
*** END OF TRANSMISSION ***