Essential Insights
- Unauthenticated attackers exploited CVE-2026-63077 in TeamCity to remotely execute OS commands, leading to widespread data breaches and credential theft.
- Threat actors accessed and compromised sensitive data, including user personal info, source code, and cloud credentials from JetBrains’ Cadence backups from 2024.
- The attack enabled unauthorized cloud system modifications, including repository changes, secret disclosures, and IAM role alterations, increasing risk of targeted cyberattacks and data exfiltration.
Threat Overview, Attack Techniques, and Targets
Threat actors exploited a critical vulnerability, CVE-2026-63077, in TeamCity to breach JetBrains’ Cadence environment. The vulnerability has a high CVSS score of 9.8 and allows an attacker to bypass authentication by deserializing untrusted data. This flaw is actively being used in the wild, and it was added to the U.S. Cybersecurity and Infrastructure Security Agency’s KEV catalog.
The attack took place between August 8 and 24, 2026. The threat actors accessed data stored in the Cadence server backup from 2024. They obtained unauthorized access to storage containing user credentials, project source code, and personal data. The targets included Cadence’s cloud environment, personal information of users, and associated AWS credentials. They also accessed source code synchronized from PyCharm projects linked to Cadence.
The attackers used the breach to extract AWS IAM credentials and other secrets. They accessed multiple AWS S3 buckets and possibly compromised source code and project configurations. Their activities indicate a focus on gaining deep access to development environments and cloud resources.
Impact, Security Implications, and Remediation Guidance
The breach exposes sensitive data, including personal information and user credentials. The compromise of AWS credentials could allow attackers to access cloud storage and other connected systems. There is also a risk of misuse of this information for targeted attacks such as phishing or impersonation.
JetBrains has responded by invalidating all access tokens related to the compromised Cadence plugin and advising users to revoke and rotate all credentials. They have warned users to treat all Cadence executions as untrusted and to review connected systems for suspicious activities. Users should check their AWS accounts, source code repositories, and cloud environments for unauthorized actions.
Because the detailed remediation steps are not provided, users are advised to seek guidance from the relevant vendors or authorities. It is important to patch the affected TeamCity server to prevent further exploitation and to review security policies for sensitive cloud and development environments.
Stay Ahead with the Latest Tech Trends
Explore the future of technology with our detailed insights on Artificial Intelligence.
Explore past and present digital transformations on the Internet Archive.
ThreatIntel-V1
