JetBrains is warning Cadence users to revoke and rotate all credentials after attackers exploited CVE-2026-63077 in TeamCity to breach its environment and potentially access backups, source code, and secrets. The incident may have exposed personal data, AWS IAM credentials, S3 files, and PyCharm-synced project contents, prompting urgent review of connected systems and suspicious activity. #JetBrains #Cadence #TeamCity #CVE-2026-63077
Keypoints
- JetBrains says Cadence users should revoke or rotate all credentials and secrets immediately.
- Attackers exploited CVE-2026-63077 in TeamCity to access JetBrainsβ Cadence environment.
- The compromised data may include personal information, backups, source code, and AWS IAM credentials.
- JetBrains invalidated Cadence plugin access tokens and shut down the affected server.
- Users should inspect AWS, S3, repositories, and other connected systems for suspicious activity.
Read More: https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html