INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Attackers Exploited Unpatched TeamCity to Extract AWS Credentials from JetBrains
| 2026-09-05 16:55 HIGH HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
Unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach JetBrains Cadence via unpatched TeamCity, extracting AWS credentials. The attack occurred on August 23, 2026, and was discovered by JetBrains on the same day. The attackers accessed data contained in the Cadence server backup from 2024, including personal data of current users such as usernames, real names, email addresses, last-login timestamps, and last accessed IP addresses, as well as a full backup of the Cadence server dating from 2024 containing credentials, configuration, artifacts, logs, or other sensitive information. The attack works by exploiting the deserialization of untrusted data vulnerability in TeamCity, allowing an attacker to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process. As a result, JetBrains is urging Cadence users to revoke and rotate all credentials following this security incident.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-63077 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ap•••••.com
150.109.•••.•••
62.210.•••.•••
152.233.•••.•••
43.153.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-63077CVE-2026-63077
Target & Sectors
Global Scope
Incident Timeline
August 5, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the T1588.006 - Vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August 5, 2026.
Click on any entity below to view its context and source!
attribution
the Known Exploited
The security flaw has since
come under active exploitation
in the wild, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) adding it to the Known Exploited Vulnerabilities (KEV) catalog on August 5, 2026.
tactic
T1588.006 - Vulnerabilities
The security flaw has since
come under active exploitation
in the wild, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) adding it to the Known Exploited Vulnerabilities (KEV) catalog on August 5, 2026.
attribution
KEV
The security flaw has since
come under active exploitation
in the wild, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) adding it to the Known Exploited Vulnerabilities (KEV) catalog on August 5, 2026.
2026/08/06
Unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach JetBrains Cadence, extracting AWS credentials.
Click on any entity below to view its context and source!
tactic
Data Breach
Ravie Lakshmanan
Sep 05, 2026
Data Breach / Identity Security
JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment.
organisation
Data Breach / Identity Security
Ravie Lakshmanan
Sep 05, 2026
Data Breach / Identity Security
JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment.
general_metric
05 Sep
Ravie Lakshmanan
Sep 05, 2026
Data Breach / Identity Security
JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment.
August 8, 2026
Threat actors exploited unpatched TeamCity instances to gain access to JetBrains Cadence, subsequently extracting AWS credentials.
between August 8 and
Attackers breached JetBrains Cadence via unpatched TeamCity between August 8 and 24, 2026.
August 23, 2026
Threat actors exploited an unpatched TeamCity instance to breach JetBrains Cadence, extracting AWS credentials.
Sep 05, 2026
Threat actors exploited an unpatched vulnerability in JetBrains TeamCity to gain unauthorized access to a Cadence instance, allowing them to extract AWS credentials.
24, 2026
Attackers breached JetBrains Cadence via unpatched TeamCity between August 8 and 24, 2026.
2026/09/05
Threat actors exploited the unpatched TeamCity vulnerability (CVE-2026-63077) to breach JetBrains Cadence, extracting AWS credentials and accessing sensitive data.
Click on any entity below to view its context and source!
organisation
Unpatched TeamCity
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials.
organisation
Extracting AWS
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials.
infrastructure
9.8
The attack, per the software development company, involved the exploitation of
CVE-2026-63077
(CVSS score: 9.8) to breach the affected Cadence environments.
infrastructure
150.109.230
…2026, onwards, particularly authentication or activity using credentials previously stored in or accessible through Cadence
IP addresses associated with observed exploitation activity:
150.109.230.104
43.153.227.206
62.210.127.48
210.247.242.190
15.235.225.205
152.233.30.18
Authentication or other activity from unexpected IP addresses or locations
Unexpected repos…
infrastructure
43.153.227
…ticularly authentication or activity using credentials previously stored in or accessible through Cadence
IP addresses associated with observed exploitation activity:
150.109.230.104
43.153.227.206
62.210.127.48
210.247.242.190
15.235.225.205
152.233.30.18
Authentication or other activity from unexpected IP addresses or locations
Unexpected repository clones or do…
infrastructure
62.210.127
…ication or activity using credentials previously stored in or accessible through Cadence
IP addresses associated with observed exploitation activity:
150.109.230.104
43.153.227.206
62.210.127.48
210.247.242.190
15.235.225.205
152.233.30.18
Authentication or other activity from unexpected IP addresses or locations
Unexpected repository clones or downloads, and unex…
infrastructure
210.247.242
…ity using credentials previously stored in or accessible through Cadence
IP addresses associated with observed exploitation activity:
150.109.230.104
43.153.227.206
62.210.127.48
210.247.242.190
15.235.225.205
152.233.30.18
Authentication or other activity from unexpected IP addresses or locations
Unexpected repository clones or downloads, and unexpected commits t…
infrastructure
15.235.225
…als previously stored in or accessible through Cadence
IP addresses associated with observed exploitation activity:
150.109.230.104
43.153.227.206
62.210.127.48
210.247.242.190
15.235.225.205
152.233.30.18
Authentication or other activity from unexpected IP addresses or locations
Unexpected repository clones or downloads, and unexpected commits to repositories
C…
infrastructure
152.233.30
…ored in or accessible through Cadence
IP addresses associated with observed exploitation activity:
150.109.230.104
43.153.227.206
62.210.127.48
210.247.242.190
15.235.225.205
152.233.30.18
Authentication or other activity from unexpected IP addresses or locations
Unexpected repository clones or downloads, and unexpected commits to repositories
Changes to reposit…
organisation
Cadence
IP
…red the following indicators of compromise -
Activity occurring from August 8, 2026, onwards, particularly authentication or activity using credentials previously stored in or accessible through Cadence
IP addresses associated with observed exploitation activity:
150.109.230.104
43.153.227.206
62.210.127.48
210.247.242.190
15.235.225.205
152.233.30.18
Authentica…
organisation
Unexpected
…associated with observed exploitation activity:
150.109.230.104
43.153.227.206
62.210.127.48
210.247.242.190
15.235.225.205
152.233.30.18
Authentication or other activity from unexpected IP addresses or locations
Unexpected repository clones or downloads, and unexpected commits to repositories
Changes to repository secrets, webhooks, collaborators, or permissions
New…
organisation
API
…Unexpected repository clones or downloads, and unexpected commits to repositories
Changes to repository secrets, webhooks, collaborators, or permissions
New or modified personal access tokens, API tokens, or SSH keys in external services
New service accounts created in external services
Unexpected changes to cloud IAM roles, policies, or permissions
Unexpected access to cloud storage…
organisation
SSH
…pository clones or downloads, and unexpected commits to repositories
Changes to repository secrets, webhooks, collaborators, or permissions
New or modified personal access tokens, API tokens, or SSH keys in external services
New service accounts created in external services
Unexpected changes to cloud IAM roles, policies, or permissions
Unexpected access to cloud storage, including S3…
organisation
AWS
…ce accounts created in external services
Unexpected changes to cloud IAM roles, policies, or permissions
Unexpected access to cloud storage, including S3 buckets and objects, in services such as AWS and Google Cloud
Unexpected publication or modification of packages or releases
Besides rotating all credentials, users are being asked to review connected systems for suspicious activity,…
organisation
Google Cloud
Unexpected
…nts created in external services
Unexpected changes to cloud IAM roles, policies, or permissions
Unexpected access to cloud storage, including S3 buckets and objects, in services such as AWS and Google Cloud
Unexpected publication or modification of packages or releases
Besides rotating all credentials, users are being asked to review connected systems for suspicious activity, specific…
organisation
Cadence
"They should also treat all executions, including their inputs and outputs in your Cadence project, as potentially untrusted."
"As the threat actors gained access to the Cadence server, any credentials or secrets stored in Cadence, contained in the compromised backup, or made available to executions on the affected server should be considered compromised and must be revoked or rotated.
organisation
JetBrains
"
Cadence
is a JetBrains-hosted cloud computing service that integrates with PyCharm via an optional plugin to let developers run machine learning and heavy workloads on cloud GPUs directly from their IDE.
organisation
IDE
"
Cadence
is a JetBrains-hosted cloud computing service that integrates with PyCharm via an optional plugin to let developers run machine learning and heavy workloads on cloud GPUs directly from their IDE.
organisation
IP
…the information the threat actor has been "confirmed" to have accessed or compromised -
Personal data, including usernames, real names, email addresses, last-login timestamps, and last accessed IP addresses
A full backup of the Cadence server dating from 2024, which contains credentials, configuration, artifacts, logs, or other data
Multiple AWS IAM users and associated credentials/secr…
organisation
Multiple AWS IAM
…l addresses, last-login timestamps, and last accessed IP addresses
A full backup of the Cadence server dating from 2024, which contains credentials, configuration, artifacts, logs, or other data
Multiple AWS IAM users and associated credentials/secrets used with Cadence extracted from the 20224 backup, including IAM users belonging to JetBrains employees who used the service
Files stored i…
organisation
IAM
…last-login timestamps, and last accessed IP addresses
A full backup of the Cadence server dating from 2024, which contains credentials, configuration, artifacts, logs, or other data
Multiple AWS IAM users and associated credentials/secrets used with Cadence extracted from the 20224 backup, including IAM users belonging to JetBrains employees who used the service
Files stored in S3 buckets…
organisation
S3
…a
Multiple AWS IAM users and associated credentials/secrets used with Cadence extracted from the 20224 backup, including IAM users belonging to JetBrains employees who used the service
Files stored in S3 buckets within JetBrains AWS accounts used by Cadence
JetBrains also cautioned that the attackers may have accessed source code synchronized from PyCharm projects to the affected server.
organisation
JetBrains AWS
…a
Multiple AWS IAM users and associated credentials/secrets used with Cadence extracted from the 20224 backup, including IAM users belonging to JetBrains employees who used the service
Files stored in S3 buckets within JetBrains AWS accounts used by Cadence
JetBrains also cautioned that the attackers may have accessed source code synchronized from PyCharm projects to the affected server.
organisation
Cadence
JetBrains
…a
Multiple AWS IAM users and associated credentials/secrets used with Cadence extracted from the 20224 backup, including IAM users belonging to JetBrains employees who used the service
Files stored in S3 buckets within JetBrains AWS accounts used by Cadence
JetBrains also cautioned that the attackers may have accessed source code synchronized from PyCharm projects to the affected server.
organisation
PyCharm
…a
Multiple AWS IAM users and associated credentials/secrets used with Cadence extracted from the 20224 backup, including IAM users belonging to JetBrains employees who used the service
Files stored in S3 buckets within JetBrains AWS accounts used by Cadence
JetBrains also cautioned that the attackers may have accessed source code synchronized from PyCharm projects to the affected server.
organisation
the JetBrains Cadence
JetBrains has also invalidated all access tokens used by the JetBrains Cadence plugin in PyCharm to connect to Cadence.
Tactical Metrics
Metrics
infrastructure
9.8
Software Version
Click for context!
The attack, per the software development company, involved the exploitation of
CVE-2026-63077
(CVSS score: 9.8) to breach the affected Cadence environments.
Metrics
infrastructure
150.109.230
Software Version
…2026, onwards, particularly authentication or activity using credentials previously stored in or accessible through Cadence
IP addresses associated with observed exploitation activity:
150.109.230.104
43.153.227.206
62.210.127.48
210.247.242.190
15.235.225.205
152.233.30.18
Authentication or other activity from unexpected IP addresses or locations
Unexpected repos…
Metrics
infrastructure
43.153.227
Software Version
…ticularly authentication or activity using credentials previously stored in or accessible through Cadence
IP addresses associated with observed exploitation activity:
150.109.230.104
43.153.227.206
62.210.127.48
210.247.242.190
15.235.225.205
152.233.30.18
Authentication or other activity from unexpected IP addresses or locations
Unexpected repository clones or do…
Metrics
infrastructure
62.210.127
Software Version
…ication or activity using credentials previously stored in or accessible through Cadence
IP addresses associated with observed exploitation activity:
150.109.230.104
43.153.227.206
62.210.127.48
210.247.242.190
15.235.225.205
152.233.30.18
Authentication or other activity from unexpected IP addresses or locations
Unexpected repository clones or downloads, and unex…
Metrics
infrastructure
210.247.242
Software Version
…ity using credentials previously stored in or accessible through Cadence
IP addresses associated with observed exploitation activity:
150.109.230.104
43.153.227.206
62.210.127.48
210.247.242.190
15.235.225.205
152.233.30.18
Authentication or other activity from unexpected IP addresses or locations
Unexpected repository clones or downloads, and unexpected commits t…
Metrics
infrastructure
15.235.225
Software Version
…als previously stored in or accessible through Cadence
IP addresses associated with observed exploitation activity:
150.109.230.104
43.153.227.206
62.210.127.48
210.247.242.190
15.235.225.205
152.233.30.18
Authentication or other activity from unexpected IP addresses or locations
Unexpected repository clones or downloads, and unexpected commits to repositories
C…
Metrics
infrastructure
152.233.30
Software Version
…ored in or accessible through Cadence
IP addresses associated with observed exploitation activity:
150.109.230.104
43.153.227.206
62.210.127.48
210.247.242.190
15.235.225.205
152.233.30.18
Authentication or other activity from unexpected IP addresses or locations
Unexpected repository clones or downloads, and unexpected commits to repositories
Changes to reposit…
Intelligence Sources
The Hacker News
2026-09-05
AlienVault OTX
2026-09-05
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T10:56
Comprehensive Tactical Telemetry
Highly Correlated Entities
20x
organisation
Identified Entity
Unpatched TeamCity
entity
9x
timeline
Temporal Reference
2026/08/06
date
7x
infrastructure
Software Version
9.8
version
4x
tactic
Cyber Operation Type
Data Breach
tactic
3x
attribution
Attributing Entity
the U.S. Cybersecurity and Infrastructure Security Agency
authority
2x
tactic
MITRE ATT&CK Technique
T1589.001 - Credentials
technique
Contextual Telemetry
Context Block
3 METRICS
general metric
Sep
5
sep
vulnerability
Exploited CVE
CVE-2026-63077
cve
general metric
Score
10
score
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.