← BACK TO FEED
TAG

aws credentials1 article

JetBrains Left a Critical Flaw Unpatched. Attackers Walked Off With AWS Keys.

JetBrains suffered a security breach of its Cadence cloud computing service after unidentified attackers exploited a critical unpatched TeamCity vulnerability (CVE-2026-63077, CVSS 9.8), gaining unauthorized access between August 8–24, 2026. The attackers extracted sensitive data including personal user information, a full 2024 Cadence server backup containing AWS IAM credentials, S3 bucket files, and potentially users' PyCharm project source code. JetBrains is urging all affected Cadence users to immediately revoke and rotate credentials, audit connected cloud services and repositories for suspicious activity, and treat all past executions as potentially compromised.

6 Sept 2026