← BACK TO FEED
JetBrainsTeamCitysupply chain securityAWS credentialsCVE-2026-63077

JetBrains Left a Critical Flaw Unpatched. Attackers Walked Off With AWS Keys.

JetBrains suffered a security breach of its Cadence cloud computing service after unidentified attackers exploited a critical unpatched TeamCity vulnerability (CVE-2026-63077, CVSS 9.8), gaining unauthorized access between August 8–24, 2026. The attackers extracted sensitive data including personal user information, a full 2024 Cadence server backup containing AWS IAM credentials, S3 bucket files, and potentially users' PyCharm project source code. JetBrains is urging all affected Cadence users to immediately revoke and rotate credentials, audit connected cloud services and repositories for suspicious activity, and treat all past executions as potentially compromised.

JetBrains is telling users of its Cadence cloud service to treat every credential, secret, and code execution as compromised following a breach last month that exploited a critical, unpatched vulnerability in TeamCity. The attacker wasn't particularly sophisticated in their approach — they just used a door that JetBrains had left unlocked.

The vulnerability in question is CVE-2026-63077, scoring a near-perfect 9.8 on the CVSS scale. It's a deserialization flaw that lets an unauthenticated attacker bypass authentication entirely and run arbitrary OS commands with the privileges of the TeamCity server process. CISA added it to the Known Exploited Vulnerabilities catalogue on August 5th. JetBrains discovered it being used against their own infrastructure on August 23rd. The intrusion window ran from August 8th to the 24th.

For those unfamiliar, Cadence is a JetBrains-hosted service that hooks into PyCharm via a plugin, letting developers offload machine learning and GPU-heavy workloads to cloud infrastructure directly from their IDE. It connects to real AWS infrastructure, stores real credentials, and syncs real source code. All of which the attacker now potentially has.

The confirmed damage is considerable. The threat actor accessed personal data including usernames, real names, email addresses, login timestamps, and last-known IP addresses. They got into a full 2024 backup of the Cadence server — which contained credentials, configuration data, artifacts, and logs. They extracted multiple AWS IAM users and their associated secrets from that backup, including accounts belonging to JetBrains employees. They also accessed files stored in S3 buckets inside JetBrains' own AWS accounts.

For users who had PyCharm syncing project files to Cadence for cloud execution, source code may also have been exposed. That's not a trivial concern. Project files often contain hardcoded secrets, environment configurations, and API tokens that developers never intended to be accessible outside their local machine.

JetBrains has taken the affected server offline, invalidated all Cadence plugin access tokens, and rotated its own internal credentials. The company has also published a list of IP addresses linked to the observed exploitation activity, including addresses across Hong Kong, France, Japan, Canada, and Chile. No attribution has been made.

What's harder to explain away is the acknowledgement buried in JetBrains' disclosure: the server should have been patched as part of their own internal vulnerability response process. It wasn't. No explanation was offered for why not. A critical, publicly known vulnerability sitting unpatched on an internet-facing server that stores AWS credentials and customer source code is not a minor operational slip.

JetBrains is advising affected users to immediately revoke and rotate all credentials and secrets used in Cadence, audit AWS accounts, S3 buckets, deployment environments, and container registries for signs of misuse, review source code repositories for unauthorised changes during the August 8-24 window, and watch for signs of new service accounts, modified IAM roles, or unexpected cloud storage access.

The company also flagged the secondary risk: exposed names and email addresses increase the likelihood of targeted phishing and social engineering against affected users. If you used Cadence and haven't already acted, now is probably the time.

READ NEXT
Chinese Hackers Weaponised a Flaw in Tencent's Sogou to Drop a Backdoor on Hundreds of Millions of Potential TargetsStyleSmuggler: Rust-Powered Backdoor Hits Adobe Commerce Stores via Unpatched Zero-DayTrezor's Shipping Partner Kept Data It Promised to Delete. 67,000 Customers Are Now Paying the Price.