HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

Attackers Breach JetBrains Cadence via Unpatched TeamCity Vulnerability, Steal AWS Credentials

JetBrains confirmed that threat actors leveraged a critical, unpatched TeamCity vulnerability to breach its Cadence platform and extract AWS credentials. This highlights the importance of continuous third‑party patch management and credential hygiene for audit readiness.

Verisq™ Intelligence · 📅 September 06, 2026 · 📰 thehackernews.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
thehackernews.com

Attackers Breach JetBrains Cadence via Unpatched TeamCity Vulnerability, Steal AWS Credentials

What Happened — Threat actors exploited a critical, publicly disclosed vulnerability in JetBrains TeamCity that had not been patched. The exploit gave them access to JetBrains Cadence, where they exfiltrated AWS access keys used by Cadence jobs. JetBrains has urged all Cadence users to revoke or rotate any credentials that may have been exposed.

Why It Matters for Trust & Control Assurance

  • Demonstrates a gap in third‑party patch management – a control objective that continuous assurance programs must monitor and evidence.
  • Credential compromise highlights the need for robust access‑control policies and rapid rotation processes, both essential audit artifacts.
  • Provides a real‑world case for documenting vendor‑risk oversight, supporting due‑diligence and defensible audit trails.

Who Is Affected — SaaS and developer‑tool providers that run Cadence or similar workflow engines, and any organization that integrates JetBrains TeamCity into its CI/CD pipeline.

Recommended Actions

  • Immediately revoke and rotate all AWS credentials that were used by Cadence jobs.
  • Verify that every TeamCity instance is patched to the latest security release; automate patch verification where possible.
  • Deploy continuous third‑party risk monitoring to capture patch status and retain evidence for audit readiness.

Technical Notes — The breach leveraged a critical TeamCity vulnerability (CVE‑2026‑XXXX) that allowed remote code execution on the CI server. Attackers used the foothold to access Cadence’s execution environment and extract AWS access keys stored as secrets. Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →