Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

A Critical Vulnerability in JetBrains Cadence Exposes AWS Credentials, Leaving Thousands of Developers at Risk

In a disturbing revelation, cybersecurity researchers have uncovered an alarming security breach that has compromised thousands of developers worldwide. Attackers exploited an unpatched vulnerability in JetBrains TeamCity, a popular continuous integration and continuous deployment (CI/CD) tool used by numerous organizations, to gain access to sensitive AWS credentials. The exploit allowed the attackers to extract Amazon Web Services (AWS) access keys, leaving these high-value credentials exposed to potential misuse.

The breach is believed to have occurred via an unpatched version of JetBrains TeamCity, a software development platform that enables teams to manage and automate their build, test, and deployment processes. By exploiting this vulnerability, attackers were able to extract AWS credentials stored within the affected systems, potentially granting them unfettered access to cloud infrastructure, data, and sensitive information.

The scale of the breach is concerning, as thousands of developers rely on JetBrains TeamCity for their daily work. The platform’s popularity across various industries, including software development, finance, and healthcare, means that this vulnerability could have far-reaching consequences. Moreover, AWS credentials are highly coveted by attackers due to their potential to unlock sensitive data and grant access to critical cloud resources.

Researchers note that the breach was made possible through a combination of factors, including the presence of an unpatched TeamCity instance and the storage of AWS credentials within the system. The use of cross-domain privilege escalation techniques allowed the attackers to navigate the compromised systems, ultimately leading to the extraction of sensitive AWS credentials. This attack path highlights the importance of proper security measures, including regular software updates and secure credential management practices.

The JetBrains Cadence breach serves as a stark reminder of the need for vigilance in cybersecurity. As developers increasingly rely on cloud-based services and CI/CD tools like TeamCity, it is crucial that organizations prioritize patching and maintenance to prevent similar breaches from occurring. Furthermore, storing sensitive AWS credentials securely within these systems is essential to mitigate the risk of unauthorized access.

To protect themselves against this type of attack, readers should ensure their TeamCity instances are up-to-date with the latest security patches. It’s also vital to store AWS credentials securely outside of CI/CD tools and use role-based access control mechanisms to limit exposure to sensitive data. By taking these proactive measures, developers can significantly reduce their risk of falling victim to this type of exploit.


Source: The Hacker News — 2026-09-05