← Blog · · df00tech

JetBrains Says Attackers Breached Cadence Environment via Unpatched TeamCity, Urges Credential Rotation

security-news breach

What Happened

JetBrains has disclosed that unidentified threat actors breached its Cadence environment last month by exploiting a recently disclosed critical vulnerability in TeamCity. According to JetBrains, the attackers used the compromised environment to extract AWS credentials, and the company is now urging all Cadence users to immediately revoke or rotate any credentials and secrets that may have been used to run Cadence executions.

Details on the specific TeamCity vulnerability exploited, the scope of data accessed, and attribution have not been disclosed in the reporting available at this time.

Why It Matters for Defenders

TeamCity is widely used as a CI/CD build server, and CI/CD systems routinely hold or have access to secrets, cloud credentials, and source code needed to build and deploy software. A breach of a build pipeline like Cadence's is significant because credentials embedded in or accessible to CI executions can enable lateral movement into connected cloud environments — in this case, AWS. Any organization using Cadence to run builds, or that has integrated Cadence executions with AWS resources, may have had credentials exposed and should treat this as a potential supply-chain exposure, not just an isolated incident affecting JetBrains alone.

What Defenders Should Do Now

  • If you use JetBrains Cadence, immediately revoke and rotate all credentials and secrets used in Cadence executions, as JetBrains has advised.
  • Inventory and patch any self-hosted TeamCity instances — this incident is a reminder that unpatched TeamCity servers are an active target, and prior TeamCity vulnerabilities have been mass-exploited in the past.
  • Review AWS CloudTrail and IAM activity logs for anomalous API calls, unexpected credential usage, or access from unfamiliar IP ranges/regions tied to any AWS keys that may have touched Cadence pipelines.
  • Audit CI/CD systems generally for long-lived or overly-broad cloud credentials, and consider moving toward short-lived, scoped credentials (e.g., OIDC-based federation) for build pipelines.
  • Monitor for follow-on activity such as unauthorized resource creation, data exfiltration from S3, or new IAM users/roles created using potentially compromised AWS credentials.

Developing Story

This is a developing situation with limited public detail on the exploited TeamCity vulnerability, breach timeline, and full impact. We will continue to track updates. For the original report, see The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.