JetBrains warns Cadence users to rotate credentials after security breach

 

JetBrains warns Cadence users to rotate credentials after security breach

JetBrains is urging users of its Cadence cloud service to revoke and rotate their credentials after attackers breached the company’s environment by exploiting a critical TeamCity vulnerability.

The intrusion took place between August 8 and 24, 2026, with the attackers exploiting CVE-2026-63077, a critical flaw that can allow unauthenticated attackers to bypass authentication and execute commands on vulnerable TeamCity servers.

JetBrains said the threat actors accessed a 2024 Cadence server backup containing credentials, configuration data, logs and other information. They may also have accessed user data, AWS credentials, S3 storage and source code synchronized from PyCharm projects.

The company has taken the affected Cadence server offline and revoked access tokens used by the Cadence plugin for PyCharm.

JetBrains is advising impacted users to rotate all credentials and secrets that may have been used with Cadence. Users should also check AWS accounts, S3 buckets, deployment systems and code repositories for suspicious activity.

Currently, it’s not clear, who is behind the attack.

Last week, Coder disclosed that attackers breached its Cloudflare infrastructure and added unauthorized registry servers. The servers delivered malicious Terraform modules designed to steal users’ credentials and send them to a remote server. A limited number of users may have been affected if they used Coder’s main module registry and updated components while the malicious code was available.

Back to the list