importantSYS.SOURCE: The Hacker News• 2026-09-05T22:22:33+05:30
Unpatched TeamCity Vulnerability Exploited in JetBrains Cadence Breach, Leading to AWS Credential Theft
Attackers exploited a critical unpatched TeamCity vulnerability (CVE-2026-63077) to breach JetBrains Cadence, extracting AWS credentials and compromising user data. JetBrains urged immediate credential rotation and system audits due to potential exposure of sensitive information.
JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment.
"Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
*** END OF TRANSMISSION ***