AWS Security Digest·Week 36 of 2026·Aug 31 - Sep 6, 2026·6 items

    JetBrains' Cadence Breach Exposes AWS Credentials, Not Just Code

    JetBrains concludes its investigation into a three-week breach of its Cadence CI/CD service, confirming attackers compromised AWS IAM users and credentials and accessed files in JetBrains-owned S3 buckets, alongside PyCharm source code and user data. Four new AWS security bulletins close the month, and AWS opens beta registration for its new AI Business Strategist certification.

    In this issue1critical1high3medium1info

    Highlights

    2 items
    $ tail -f /var/log/aws-security.log
    critical/Incident/

    JetBrains Confirms AWS Credentials Compromised in Cadence Breach

    JetBrains concluded its investigation into an August 8-24 breach of Cadence, its cloud CI/CD service, exploited via CVE-2026-63077, a critical unauthenticated remote-code-execution flaw in TeamCity. Attackers accessed a full 2024 server backup and, per JetBrains, "compromised multiple AWS IAM users and associated credentials/secrets used with Cadence" and "accessed files stored in S3 buckets within JetBrains AWS accounts used by Cadence."

    JetBrains also says attackers "may have accessed source code synchronized from PyCharm projects to the affected server" and exposed personal data (usernames, names, emails, last-login timestamps and IPs) for affected users. JetBrains says it does not currently know whether attackers accessed storage buckets in customer AWS accounts, and has advised users to rotate all credentials used in Cadence executions.

    IAMS3
    info/Feature Launch/

    AWS Opens Beta Registration for AI Business Strategist Certification

    AWS opened beta registration on September 1 for its new AWS Certified AI Business Strategist credential, aimed at non-technical professionals who evaluate, champion, and scale AI initiatives - line-of-business leaders, sales, consulting, and program management roles with at least six months of AI-adjacent experience.

    The beta exam (85 questions, 170 minutes, $50) begins delivery September 29, with no coding or prior AWS certification required.

    CVEs & Vulnerabilities

    4 items
    $ cat /var/reports/CVE_REPORT.txt
    high/CVE/

    CVE-2026-85656: Command Injection in the Log4j Hotpatch Tool for Amazon Linux

    The log4j-cve-2021-44228-hotpatch tool, which patches running Log4j processes against CVE-2021-44228 without requiring restarts, can be tricked into running arbitrary commands as root if a Java process's executable path contains embedded newline characters. Affects versions up to 1.3-8.amzn2; fixed in 1.3-9.amzn2 (advisory ALAS2-2026-3784).

    Affected
    • log4j-cve-2021-44228-hotpatch <= 1.3-8.amzn2
    Fixed In
    • log4j-cve-2021-44228-hotpatch 1.3-9.amzn2
    Amazon Linux
    medium/CVE/

    CVE-2026-85781: EFS CSI Driver Could Delete Unauthorized Directories

    When deployed with the non-default --delete-access-point-root-dir=true setting, the Amazon EFS CSI Driver's controller did not verify that a PersistentVolume's access point belonged to the file system named in the same volume handle. An authenticated Kubernetes user with PersistentVolume-creation rights could exploit this to recursively delete directories on EFS file systems they were not authorized to access; underlying EFS access controls were not bypassed. Affects the driver up to v3.4.0; fixed in v3.4.1.

    Affected
    • Amazon EFS CSI Driver <= 3.4.0
    Fixed In
    • Amazon EFS CSI Driver 3.4.1
    EFSEKS
    medium/CVE/

    CVE-2026-85786: Amazon Ion Java DoS Fix Was Incomplete

    Ion Java 1.12.0's GZIP auto-decompression opt-out, shipped to fix the earlier CVE-2026-75936 memory-amplification DoS, proved insufficient: highly compressed data expansion can still exhaust memory. Fixed properly in ion-java 1.12.1.

    Affected
    • ion-java < 1.12.1
    Fixed In
    • ion-java 1.12.1
    Ion Java
    medium/CVE/

    CVE-2026-85787: SQL Validation Bypass in postgres-mcp-server

    An incomplete list of disallowed inputs in postgres-mcp-server's SQL validation component let an attacker inject SQL that modifies data beyond the tool's intended read-only scope, provided an authenticated user interacts with the MCP server on attacker-supplied content. Affects all PyPI releases below 1.1.7; fixed in 1.1.7. AWS also recommends running the server under a minimal-privilege Postgres role rather than superuser credentials.

    Affected
    • postgres-mcp-server < 1.1.7
    Fixed In
    • postgres-mcp-server 1.1.7
    MCP

    Key Takeaway

    1 item
    $ cat WEEKLY_SUMMARY.md

    The JetBrains Cadence breach is a reminder that CI/CD compromise routinely means cloud-credential compromise: a full 2024 backup handed attackers live AWS IAM secrets years after it was taken. If Cadence touched your AWS accounts, rotate everything it could have accessed rather than waiting for JetBrains to confirm scope - "we do not currently know" is not the same as "no."

    Filed Under
    JetBrainsCadenceTeamCityIAMAmazon LinuxEFSMCPIon Java

    Need Custom Security Briefings?

    These weekly digests are a starting point. Contact us for tailored threat briefings, security assessments, and architectural guidance for your AWS environment.