A Critical Vulnerability in JetBrains Cadence Exposed Thousands of AWS Credentials
Thousands of developers and organizations using JetBrains’ project management tool, Cadence, have been left vulnerable to a critical security breach after attackers exploited an unpatched vulnerability in TeamCity, a closely related service. The attack allowed hackers to extract sensitive AWS credentials, compromising the security of multiple projects and potentially paving the way for further exploitation.
The story begins with TeamCity, a popular continuous integration and deployment tool developed by JetBrains. A recently discovered vulnerability in TeamCity’s authentication mechanism enabled attackers to bypass security checks and gain unauthorized access to connected Cadence instances. Once inside, they could extract sensitive AWS credentials, which are used to manage access to Amazon Web Services (AWS) resources.
Cadence, a cloud-based project management platform also developed by JetBrains, relies heavily on TeamCity for continuous integration and deployment processes. When an attacker gains access to a connected TeamCity instance, they can easily move laterally into the Cadence environment. The severity of this vulnerability lies in its ability to expose sensitive AWS credentials, allowing attackers to gain control over multiple projects and potentially use them as stepping stones for further exploitation.
The consequences of this attack are far-reaching, affecting thousands of developers and organizations worldwide who rely on JetBrains’ tools for their development processes. A breach of this nature can lead to intellectual property theft, data tampering, and even ransomware attacks. Moreover, the fact that attackers were able to exploit an unpatched vulnerability highlights the importance of timely software updates and security patches.
The incident serves as a stark reminder of the need for developers to prioritize security in their development processes. It is essential for organizations to stay up-to-date with software updates and security patches, especially when using interconnected services like TeamCity and Cadence. By taking proactive measures to secure their environments, developers can minimize the risk of such attacks and prevent potential data breaches.
To protect yourself from similar attacks, make sure to regularly review your development environment’s dependencies and update them as soon as possible. Keep an eye on software updates and security patches for all interconnected services, and consider implementing additional security measures, such as multi-factor authentication or access controls, to add an extra layer of protection. Remember that preventing a breach is always better than responding to one – stay vigilant and keep your development environment secure.
Source: The Hacker News — 2026-09-05