Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials (opens in a new tab)
Why readIf you run JetBrains Cadence, every credential and secret exposed to an execution is compromised and needs rotating now.
Attackers exploited CVE-2026-63077, a recently disclosed critical TeamCity flaw, against an unpatched JetBrains instance and reached the Cadence environment, a hosted cloud compute service that runs ML and GPU workloads from PyCharm. JetBrains is telling users to revoke or rotate all credentials and secrets used in Cadence executions, including anything held in the compromised backup, and to treat past execution inputs and outputs as untrusted. The wider lesson is that a vendor's own unpatched CI server became the path into a customer-facing service, so check your TeamCity patch level in the same pass.