<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🔴 Critical: Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials]]></title><description><![CDATA[<p dir="auto">JetBrains has disclosed a security incident affecting its Cadence service, urging all users to immediately revoke and rotate any credentials or secrets tied to their execution workflows. The breach, discovered last month, involved unknown attackers exploiting a recently disclosed critical vulnerability in TeamCity to gain access to JetBrains' own environment.</p>
<p dir="auto">The company confirmed that the threat actors leveraged the unpatched TeamCity flaw to infiltrate internal systems, ultimately extracting AWS credentials. While JetBrains has not specified the exact scope of the compromise, the advisory stresses that any credentials used for Cadence executions should be treated as potentially exposed.</p>
<p dir="auto">Affected users are advised to take the following actions:</p>
<ul>
<li>Revoke and rotate all credentials and secrets associated with Cadence executions immediately.</li>
<li>Audit recent activity logs for any unauthorized access or unusual API calls linked to AWS resources.</li>
<li>Review TeamCity server configurations for signs of tampering or backdoor accounts.</li>
</ul>
<p dir="auto"><em>Cadence</em> is JetBrains' managed service for running background jobs and scheduled tasks, often used in CI/CD pipelines. The incident highlights the cascading risk of unpatched infrastructure tools, as a single overlooked update can expose downstream cloud services.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Has your organization audited its TeamCity and CI/CD credential stores since this disclosure, and what steps are you taking to verify no third-party access paths remain?</p>
]]></description><link>https://xploitlk.com/topic/228/critical-attackers-breached-jetbrains-cadence-via-unpatched-teamcity-extracting-aws-credentials</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 06:28:17 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/228.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 05 Sep 2026 18:30:24 GMT</pubDate><ttl>60</ttl></channel></rss>