← Back to Tech & Science

Unidentified Hackers Breach JetBrains Cadence via Unpatched TeamCity Vulnerability

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

MOSCOW — Unidentified threat actors successfully breached the infrastructure of JetBrains Cadence on Sept. 5, 2026, exploiting a critical security flaw in a TeamCity server to extract AWS credentials and other sensitive data. The incident marks a significant compromise of the software development tools provider's environment, leveraging an unpatched vulnerability that allowed attackers to bypass authentication controls.

The attack vector centered on CVE-2026-63077, a deserialization of untrusted data vulnerability within the TeamCity continuous integration and delivery platform. Security analysis indicates that the threat actors utilized this flaw to execute arbitrary commands on the affected server. By gaining unauthorized access to the system, the intruders were able to harvest Amazon Web Services (AWS) credentials stored within the environment. These credentials likely provided a pathway for further lateral movement or data exfiltration across the company's cloud infrastructure.

JetBrains, a Russian-origin software development tools company with global operations, has not yet issued a detailed public statement regarding the full scope of the data loss or the specific systems impacted beyond the initial breach confirmation. The incident occurred at approximately 16:59 UTC on Sept. 5, though the duration of the attackers' presence within the network remains under investigation.

The exploitation of CVE-2026-63077 highlights a broader trend of attackers targeting build servers to compromise software supply chains. TeamCity instances are widely used by development teams to automate the building, testing, and deployment of software code. A vulnerability allowing arbitrary command execution in such an environment poses severe risks, as it can grant attackers access to source code repositories, API keys, and production credentials.

The breach has raised immediate concerns regarding the integrity of the software artifacts produced by JetBrains Cadence during the window of compromise. While the specific volume of data extracted is not yet quantified, the theft of AWS credentials suggests a potential for unauthorized access to cloud-hosted applications and databases associated with the company's operations.

Security experts are urging organizations running TeamCity to immediately apply available patches or implement compensating controls to mitigate the risk of similar exploitation. The incident underscores the critical importance of timely vulnerability management in continuous integration pipelines, where unpatched servers can serve as a primary entry point for sophisticated cyberattacks.

Questions remain regarding whether the stolen AWS credentials have been used to access third-party systems or if the threat actors established persistent backdoors within JetBrains' network. As investigators work to contain the breach and assess the damage, the cybersecurity community is monitoring for any signs of data leakage or unauthorized activity linked to the compromised credentials.

Discussion

0 / 2000