CuraSec

Act active

JetBrains Cadence Breached via TeamCity Flaw; AWS Creds Extracted

2026-09-06 14:08 UTC · The Hacker News · read the source ↗ #teamcity#supply-chain#credential-theft
  • Engineer — Act: If you use JetBrains Cadence, immediately revoke and rotate all credentials and secrets used in Cadence executions; also patch any self-hosted TeamCity instances to eliminate the exploited critical vulnerability.
  • SOC/IR — Act: If Cadence is in your environment, treat extracted AWS credentials as compromised and hunt for anomalous IAM activity or unexpected AWS API calls originating from CI/CD workloads since last month’s breach window.
  • Leader — Act: Confirm whether your organization uses JetBrains Cadence, request an incident attestation from JetBrains, and brief leadership on potential exposure of AWS credentials and CI/CD secrets before they read it elsewhere.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.