Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Exploited Cadence Service: JetBrains Urges Users to Revoke and Rotate Credentials Following Breach by Unpatched TeamCity




A critical security incident has been reported involving the JetBrains Cadence service, which was breached by unidentified threat actors who exploited a recently disclosed critical vulnerability in TeamCity. JetBrains is urging users to revoke and rotate all credentials and secrets that may have been used to run their Cadence executions and treat all executions as potentially untrusted. The breach highlights the importance of keeping all software up to date and implementing robust security measures to prevent similar breaches in the future.

  • Unidentified threat actors exploited a critical TeamCity vulnerability (CVE-2026-63077) to breach the JetBrains Cadence service.
  • The breach resulted in the theft of credentials, configuration, artifacts, logs, and other data, as well as potential access to personal data.
  • The threat actors accessed data from 2024, including AWS IAM users and associated credentials, and may have accessed source code and other sensitive information.
  • JetBrains is urging users to revoke and rotate credentials, treat all executions as potentially untrusted, and review connected systems for suspicious activity.
  • The incident highlights the importance of proactive security measures to prevent similar breaches in the future.



  • A critical security incident has been reported involving the JetBrains Cadence service, a cloud computing platform used by developers to run machine learning and heavy workloads on cloud GPUs. The breach, which occurred between August 8 and 24, 2026, was perpetrated by unidentified threat actors who exploited a recently disclosed critical vulnerability in TeamCity, a service provided by JetBrains.

    The vulnerability, identified as CVE-2026-63077, has a CVSS score of 9.8, indicating a high level of severity. The deserialization of untrusted data vulnerability allows an unauthenticated attacker with access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process.

    According to JetBrains, the threat actors gained access to the Cadence server by exploiting this vulnerability. They accessed data contained in the Cadence server backup from 2024, which included credentials, configuration, artifacts, logs, or other data. The threat actors also extracted multiple AWS IAM users and associated credentials/secrets used with Cadence, as well as files stored in S3 buckets within JetBrains AWS accounts used by Cadence.

    Furthermore, the threat actors may have accessed source code synchronized from PyCharm projects to the affected server, which could have inadvertently exposed code, credentials, or configurations. JetBrains has cautioned that the attackers may have also accessed personal data, including usernames, real names, email addresses, last-login timestamps, and last accessed IP addresses.

    In response to the breach, JetBrains is urging Cadence users to revoke and rotate all credentials and secrets that may have been used to run their Cadence executions. They are also advising users to treat all executions, including inputs and outputs in their Cadence project, as potentially untrusted. Additionally, JetBrains is asking users to review connected systems for suspicious activity, specifically AWS accounts, S3 buckets, deployment environments, package/container registries, and other systems that are accessible using the revoked credentials.

    The likely consequences of the personal data exposure include an increased risk of targeted phishing, social engineering, impersonation, and other unsolicited or malicious communications using the affected names and email addresses. JetBrains has emphasized the importance of taking immediate action to protect user credentials and prevent further exploitation.

    In light of this incident, it is essential for developers and organizations using the Cadence service to take proactive measures to secure their environments. This includes patching any unpatched instances of TeamCity, revoking and rotating all credentials and secrets, and implementing robust security measures to prevent similar breaches in the future.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Exploited-Cadence-Service-JetBrains-Urges-Users-to-Revoke-and-Rotate-Credentials-Following-Breach-by-Unpatched-TeamCity-ehn.shtml

  • https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-63077

  • https://www.cvedetails.com/cve/CVE-2026-63077/


  • Published: Sat Sep 5 12:01:06 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us