A single unpatched JetBrains TeamCity server on api.cadence.jetbrains.com was exploited through CVE-2026-63077, giving attackers access to Cadence cloud infrastructure, backups, and sensitive developer secrets. The breach exposed AWS IAM credentials, S3 buckets, and potentially source code, repository tokens, package registry keys, SSH keys, and signing keys, forcing immediate credential revocation and remediation. #JetBrains #TeamCity #CVE-2026-63077 #Cadence #PyCharm
Keypoints
- An unpatched TeamCity server on api.cadence.jetbrains.com was the entry point for the attack.
- Attackers exploited CVE-2026-63077 and remained undetected from August 8 to August 24.
- The breach exposed a 2024 Cadence backup, user data, AWS IAM credentials, and S3 storage buckets.
- Compromised developer infrastructure may have exposed source code, Git tokens, package registry keys, SSH keys, and signing keys.
- JetBrains is investigating the incident and advising immediate revocation of all secrets that passed through Cadence.
Read More: https://securityonline.info/jetbrains-cadence-server-hacked/