Act
active
JetBrains Cadence Breached via TeamCity Flaw; AWS Creds Extracted
- Engineer — Act: If you use JetBrains Cadence, immediately revoke and rotate all credentials and secrets used in Cadence executions; also patch any self-hosted TeamCity instances to eliminate the exploited critical vulnerability.
- SOC/IR — Act: If Cadence is in your environment, treat extracted AWS credentials as compromised and hunt for anomalous IAM activity or unexpected AWS API calls originating from CI/CD workloads since last month’s breach window.
- Leader — Act: Confirm whether your organization uses JetBrains Cadence, request an incident attestation from JetBrains, and brief leadership on potential exposure of AWS credentials and CI/CD secrets before they read it elsewhere.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.