Unidentified threat actors exploited a recently disclosed critical vulnerability in JetBrains TeamCity to breach JetBrains' own Cadence environment. The attackers successfully extracted AWS credentials during the intrusion. JetBrains has issued an urgent advisory for all Cadence users to immediately revoke or rotate any credentials and secrets used in Cadence executions. The incident highlights the risk of unpatched CI/CD infrastructure, particularly in widely used developer tooling platforms. The breach underscores the supply chain risk posed when development pipeline tools like TeamCity are left unpatched. JetBrains has not publicly identified the threat actors responsible for the attack.
Unidentified threat actors exploited CVE-2026-63077 (CVSS 9.8), a critical deserialization of untrusted data vulnerability in JetBrains TeamCity, to breach JetBrains' own Cadence cloud computing environment. The vulnerability allows an unauthenticated attacker with access to a TeamCity server to bypass authentication checks and execute arbitrary OS commands with the privileges of the TeamCity server process. The intrusion occurred between August 8 and 24, 2026, and was discovered by JetBrains on August 23, 2026. CISA added the vulnerability to its KEV catalog on August 5, 2026. The affected server (api.cadence.jetbrains.com) was not patched as part of JetBrains' own vulnerability response. The attackers accessed a full Cadence server backup from 2024, extracted AWS IAM credentials and secrets, accessed files in S3 buckets, and potentially accessed source code synchronized from PyCharm projects. Compromised data includes personal data (usernames, real names, email addresses, last-login timestamps, last accessed IP addresses), a full 2024 Cadence server backup containing credentials/configuration/artifacts/logs, multiple AWS IAM users and associated credentials/secrets, and files stored in S3 buckets within JetBrains AWS accounts.
1. Immediately revoke or rotate all credentials and secrets that may have been used to run Cadence executions. 2. Treat all Cadence executions, including their inputs and outputs, as potentially untrusted. 3. Revoke or rotate any credentials stored in Cadence, contained in the compromised backup, or made available to executions on the affected server. 4. Review connected systems for suspicious activity, specifically AWS accounts, S3 buckets, deployment environments, package/container registries, and other systems accessible using the revoked credentials. 5. Audit source code repositories for unauthorized changes between August 8 and August 24, 2026. 6. Monitor for authentication or activity from unexpected IP addresses or locations. 7. Check for unexpected repository clones, downloads, or commits. 8. Review for changes to repository secrets, webhooks, collaborators, or permissions. 9. Inspect for new or modified personal access tokens, API tokens, or SSH keys in external services. 10. Check for new service accounts created in external services. 11. Monitor for unexpected changes to cloud IAM roles, policies, or permissions. 12. Check for unexpected access to cloud storage including S3 buckets. 13. Watch for unexpected publication or modification of packages or releases. 14. Be vigilant against targeted phishing, social engineering, and impersonation attempts using exposed names and email addresses. 15. Patch TeamCity to the version that addresses CVE-2026-63077 immediately.
150.109.230.104, 43.153.227.206, 62.210.127.48, 210.247.242.190, 15.235.225.205, 152.233.30.18, api.cadence.jetbrains.com