JetBrains warns Cadence users to change credentials after TeamCity breach

← Back to articles

JetBrains warns Cadence users to change credentials after TeamCity breach

JetBrains has confirmed that attackers exploited a critical, unpatched vulnerability in its TeamCity CI/CD platform to gain unauthorized access to the company’s Cadence workflow service and steal AWS credentials. The breach, discovered last month, prompted JetBrains to advise all Cadence users to immediately revoke or rotate any secrets used in their workflows.

The incident affected users of JetBrains Cadence, a cloud‑native orchestration tool that runs jobs on behalf of customers. By compromising TeamCity, the attackers were able to move laterally within JetBrains’ network and extract AWS access keys that could be used to access cloud resources. JetBrains has not disclosed the number of customers impacted, but the risk is that stolen keys could allow malicious actors to read, modify, or delete data stored in affected AWS accounts.

The vulnerability in TeamCity was publicly disclosed but remained unpatched on JetBrains’ internal systems at the time of the attack. This oversight allowed threat actors to execute code with elevated privileges, a common pattern in supply‑chain style breaches. JetBrains’ response includes a full patch of the TeamCity flaw, a forensic investigation, and a public advisory urging credential rotation.

Customers should treat any AWS keys that may have been used by Cadence as compromised. The recommended steps are to delete the exposed keys, generate new access keys with the minimum required permissions, and update all Cadence pipelines to use the new credentials. It is also advisable to enable multi‑factor authentication (MFA) on AWS accounts and to audit recent activity for unauthorized actions. Free tools such as the AWS IAM Access Analyzer and the credential‑checking utilities available on ComputerScams.com can help identify lingering secrets.

JetBrains has emphasized that the breach does not affect the core JetBrains IDE products and that no user‑generated source code was reported stolen. Nonetheless, the incident highlights the importance of keeping all development infrastructure up to date and regularly rotating secrets.

A practical step for anyone using cloud credentials is to enable automatic key rotation where possible and to store secrets in a dedicated vault rather than embedding them in code or configuration files.

Source: Read the original report

Safety tip: Immediately audit your cloud keys and replace any that have been in use for more than 90 days.

Scroll to Top