Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Security Breach: JetBrains Cadence Users Urged to Act

Critical Security Breach: JetBrains Cadence Users Urged to Act

Posted on September 5, 2026 By CWS

JetBrains has issued an urgent advisory for Cadence users following a significant security breach. Unidentified cyber actors exploited a critical vulnerability in TeamCity, leading to unauthorized access to Cadence’s environment. Users are strongly encouraged to revoke and rotate all credentials linked to their Cadence executions to mitigate potential risks.

Details of the Security Vulnerability

The breach was facilitated through the exploitation of a severe flaw identified as CVE-2026-63077, which carries a CVSS score of 9.8. This vulnerability enables unauthenticated attackers to bypass security checks and execute arbitrary commands on the TeamCity server. The flaw has been actively exploited, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) acknowledging it in their Known Exploited Vulnerabilities catalog as of August 5, 2026.

JetBrains discovered the compromise on August 23, 2026, and has since taken the affected Cadence server offline. The server was found to host potentially exposed credentials, necessitating urgent action from users to protect their data.

Extent of Data Compromise

The attackers accessed backups from 2024, which held sensitive information such as usernames, email addresses, and AWS credentials. This breach might have affected storage containing data linked to current users, including project source code. JetBrains’ Daniel Gallo emphasized the need to treat all stored data as potentially exposed, although the company has confirmed that no additional users were impacted beyond those previously notified.

In addition, the threat actors may have accessed source code synchronized from PyCharm projects to Cadence, posing a risk of inadvertent exposure of code, credentials, and configurations.

Recommended Actions for Users

JetBrains has invalidated all access tokens used to connect Cadence with PyCharm. Users are advised to audit their AWS accounts, source code repositories, and other systems for any unauthorized activity. This includes unexpected IP logins, access to cloud storage, and alterations in repository settings.

The security breach underscores the heightened risk of phishing and social engineering attempts using the exposed data. As a precaution, users should remain vigilant against unsolicited communications that might exploit this information.

Going forward, JetBrains is committed to addressing the vulnerabilities and enhancing their response protocols to prevent future incidents. Users are urged to stay informed and take necessary actions to secure their environments.

The Hacker News Tags:AWS credentials, Cadence breach, Cybersecurity, data exposure, JetBrains, security incident, TeamCity vulnerability

Post navigation

Previous Post: Trezor Data Breach at ShipMonk Affects 67,000 U.S. Customers
Next Post: Critical Flaws Fixed in VMware Workstation and Fusion

Related Posts

Android Spyware Asin Targets Arabic Users via Fake Apps Android Spyware Asin Targets Arabic Users via Fake Apps The Hacker News
CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution The Hacker News
BREAKING: 7,000-Device Proxy Botnet Using IoT, EoL Systems Dismantled in U.S. BREAKING: 7,000-Device Proxy Botnet Using IoT, EoL Systems Dismantled in U.S. The Hacker News
ServiceNow AI Agents Can Be Tricked Into Acting Against Each Other via Second-Order Prompts ServiceNow AI Agents Can Be Tricked Into Acting Against Each Other via Second-Order Prompts The Hacker News
Entra ID Data Protection: Essential or Overkill? Entra ID Data Protection: Essential or Overkill? The Hacker News
A New Approach to a Decade-Old Challenge A New Approach to a Decade-Old Challenge The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • MikroTik Routers Vulnerable to Unauthenticated SSH Attacks
  • Urgent Alert: Magento and Adobe Commerce Vulnerability Exploited
  • Magento and Adobe Commerce Vulnerability Exploited
  • Critical Flaws Fixed in VMware Workstation and Fusion
  • Critical Security Breach: JetBrains Cadence Users Urged to Act

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • MikroTik Routers Vulnerable to Unauthenticated SSH Attacks
  • Urgent Alert: Magento and Adobe Commerce Vulnerability Exploited
  • Magento and Adobe Commerce Vulnerability Exploited
  • Critical Flaws Fixed in VMware Workstation and Fusion
  • Critical Security Breach: JetBrains Cadence Users Urged to Act

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark