Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Data Breaches & Incidents
  5. 🔴 Critical: Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

🔴 Critical: Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

Scheduled Pinned Locked Moved Data Breaches & Incidents
aws
1 Posts 1 Posters 5 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    JetBrains has disclosed a security incident affecting its Cadence service, urging all users to immediately revoke and rotate any credentials or secrets tied to their execution workflows. The breach, discovered last month, involved unknown attackers exploiting a recently disclosed critical vulnerability in TeamCity to gain access to JetBrains' own environment.

    The company confirmed that the threat actors leveraged the unpatched TeamCity flaw to infiltrate internal systems, ultimately extracting AWS credentials. While JetBrains has not specified the exact scope of the compromise, the advisory stresses that any credentials used for Cadence executions should be treated as potentially exposed.

    Affected users are advised to take the following actions:

    • Revoke and rotate all credentials and secrets associated with Cadence executions immediately.
    • Audit recent activity logs for any unauthorized access or unusual API calls linked to AWS resources.
    • Review TeamCity server configurations for signs of tampering or backdoor accounts.

    Cadence is JetBrains' managed service for running background jobs and scheduled tasks, often used in CI/CD pipelines. The incident highlights the cascading risk of unpatched infrastructure tools, as a single overlooked update can expose downstream cloud services.

    Source: The Hacker News

    Has your organization audited its TeamCity and CI/CD credential stores since this disclosure, and what steps are you taking to verify no third-party access paths remain?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World