JetBrains Alerts Cadence Users After Security Breach
In a significant security incident last month, JetBrains has urged its Cadence users to take immediate precautions by revoking and rotating all credentials. This advisory follows the exploitation of a critical vulnerability in TeamCity, which allowed unidentified threat actors to compromise JetBrains’ own environment.
JetBrains has called for Cadence users to swiftly revoke or change any credentials and secrets tied to their Cadence executions. A company statement emphasized that all project executions, including inputs and outputs associated with Cadence, should be regarded as potentially untrustworthy. As attackers gained access to the Cadence server, any credentials or secrets—all potentially contained in a compromised backup or accessed on the affected server—must be considered at risk.
Cadence functions as a JetBrains-hosted cloud computing service that integrates seamlessly with PyCharm, enabling developers to execute machine learning tasks and other resource-intensive workloads on cloud GPUs directly within their integrated development environment (IDE).
The motive behind the breach involved the exploitation of CVE-2026-63077, a severe vulnerability with a Common Vulnerability Scoring System (CVSS) score of 9.8. This flaw in TeamCity’s server architecture allows unauthenticated individuals to bypass authentication measures, execute arbitrary OS commands, and potentially reach sensitive data. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) identified this vulnerability as an actively exploited risk, adding it to their Known Exploited Vulnerabilities catalog on August 5, 2026.
JetBrains discovered that sensitive data, dating back to 2024, was accessed by the threat actors, including project source code, email addresses, and credentials of current Cadence users. The company acknowledged the breach’s relevance to specific user groups previously contacted for precautionary measures, asserting that the scope of affected users remains unchanged.
Among the compromised information, threat actors are confirmed to have accessed personal data such as usernames, email addresses, and connection timestamps, as well as a full backup of the Cadence server. Access to AWS IAM users and associated credentials was also reported. Given the nature of the incident, there is concern that the malicious actors may have gained access to code synchronized between PyCharm projects and Cadence, exposing not only user credentials but potentially any configurations uploaded for computational tasks.
While the attackers’ identities remain unknown, JetBrains specified that the intrusion occurred between August 8 and August 24, 2026, during which the compromised Cadence server was taken offline. JetBrains acknowledged that the server should have undergone patching as part of vulnerability management strategies but provided no details regarding the failure to implement necessary updates.
In response to the breach, JetBrains invalidated all access tokens utilized by the JetBrains Cadence plugin within PyCharm and issued alerts regarding suspicious activities associated with previously stored credentials from August 8 onward. Indications of exploitation may include unexpected authentication attempts from unusual IP addresses and unauthorized changes to repository configurations.
As a precaution, JetBrains recommended that Cadence users examine connected systems for unusual activity, particularly in AWS accounts and S3 buckets affected by revoked credentials. The company emphasized the increased risk of targeted phishing attacks and social engineering tactics that may arise from this exposure, alerting users that utilizing personal data for malicious communication remains a significant concern.
In summary, this incident highlights the persistent cybersecurity challenges facing organizations and the proactive measures necessary to mitigate risks. JetBrains’ actions serve as a reminder of the critical importance of safeguarding sensitive information in the digital age, especially as cyber threats continue to evolve unabated.