BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

JetBrains: Cadence Users Must Rotate Credentials After Hack

Critical TeamCity flaw exploited, JetBrains warns Cadence users to rotate credentials.

  • JetBrains urges Cadence users to immediately revoke and rotate all credentials after attackers exploited a critical TeamCity vulnerability (CVE-2026-63077) to breach its environment.
  • The intrusion between August 8 and 24, 2026, exposed personal data, credentials, AWS IAM secrets, source code, and a full 2024 server backup.
  • CISA added the flaw to its Known Exploited Vulnerabilities catalog on August 5, 2026, as active exploitation emerged in the wild.

JetBrains is warning Cadence users to revoke and rotate all credentials after unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own cloud computing environment last month. The attack, leveraging CVE-2026-63077 (CVSS 9.8), allowed an unauthenticated attacker to bypass authentication checks and execute arbitrary OS commands on the affected server.

- Advertisement -

The Cadence service, a JetBrains-hosted cloud platform that integrates with PyCharm for running ML workloads on cloud GPUs, was compromised between August 8 and 24, 2026. JetBrains stated that the threat actor accessed a full backup of the Cadence server from 2024, which contained credentials, configuration data, and artifacts.

Consequently, attackers extracted multiple AWS IAM users and associated credentials from that backup, including IAM users belonging to JetBrains employees who used the service. JetBrains also confirmed the threat actor accessed files stored in S3 buckets within the company’s AWS accounts used by Cadence.

The company said that users should treat all executions, including their inputs and outputs, as potentially untrusted. Personal data exposed includes usernames, real names, email addresses, last-login timestamps, and last accessed IP addresses.

JetBrains has invalidated all access tokens used by the Cadence plugin in PyCharm and taken the exploited server offline. The company conceded the server should have been patched as part of its own vulnerability response efforts, but did not share details on why this did not occur.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Polish crypto veto override fails by 25 votes amid scandal

Polish lawmakers failed to override President Karol Nawrocki’s veto of crypto oversight legislation, falling...

Sonic V2.2 doubles smart contract size limits for developers

Sonic V2.2 doubles the maximum deployed contract size from 24 KiB to 48 KiB...

ByteDance Secures $29.6B Loan from 30 Banks for AI Push

TikTok parent ByteDance secured a $29.6 billion loan from nearly 30 Chinese and international...

Musk: Tesla IPO value was a thousandth of current value

Tesla stock fell roughly 6% on Friday after the Cybercab launch event in Austin...

Tesla Cybercab stock crashes 6% on NHTSA audit

Tesla stock dropped 6% in an hour after the NHTSA opened a compliance audit...

Must Read

Best Crypto Audiobooks of 2026: The Ultimate Listen & Learn Guide

You can't read Bitcoin charts while driving 70 mph on the highway. You can't study Ethereum whitepapers during your morning run. But you can...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading