JetBrains Confirms AWS Credentials Compromised in Cadence Breach
JetBrains concluded its investigation into an August 8-24 breach of Cadence, its cloud CI/CD service, exploited via CVE-2026-63077, a critical unauthenticated remote-code-execution flaw in TeamCity. Attackers accessed a full 2024 server backup and, per JetBrains, "compromised multiple AWS IAM users and associated credentials/secrets used with Cadence" and "accessed files stored in S3 buckets within JetBrains AWS accounts used by Cadence."
JetBrains also says attackers "may have accessed source code synchronized from PyCharm projects to the affected server" and exposed personal data (usernames, names, emails, last-login timestamps and IPs) for affected users. JetBrains says it does not currently know whether attackers accessed storage buckets in customer AWS accounts, and has advised users to rotate all credentials used in Cadence executions.