← Back to feed
Developer Toolsjetbrains_blogAlphaLab AI score 26/100

JetBrains Cadence Breach Exploits TeamCity Vulnerability

JetBrains confirmed unauthorized access to its Cadence cloud service between August 8–24, 2026, through exploitation of CVE-2026-63077, a critical TeamCity vulnerability allowing remote code execution. The breach exposed credentials and execution data for projects run via PyCharm's optional Cadence plugin. Affected users must rotate AWS keys, review S3 buckets, and audit repositories for unauthorized changes traced to five attacker IPs including 150.109.230.104. While api.cadence.jetbrains.com remains the only confirmed compromised server, JetBrains warns all project inputs/outputs during the period should be treated as untrusted.

Original source← Back to feed