Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
According to The Hacker News, attackers breached JetBrains' Cadence platform by exploiting an unpatched TeamCity vulnerability. The intrusion resulted in the extraction of AWS credentials. The report, published on September 5, 2026, indicates that the attackers targeted JetBrains' CI/CD infrastructure, which relies on TeamCity. The specific vulnerability exploited is not detailed in the excerpt, but the lack of a patch was a contributing factor. The theft of AWS credentials could potentially allow further unauthorized access, though the full scope of the breach is not described. This incident underscores the importance of timely patching for widely used development tools like TeamCity.
Unpatched TeamCity vulnerabilities can lead to credential theft, compromising CI/CD pipelines and cloud resources.