INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Attackers Exploited Unpatched TeamCity to Extract AWS Credentials from JetBrains

| 2026-09-05 16:55 HIGH HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
Unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach JetBrains Cadence via unpatched TeamCity, extracting AWS credentials. The attack occurred on August 23, 2026, and was discovered by JetBrains on the same day. The attackers accessed data contained in the Cadence server backup from 2024, including personal data of current users such as usernames, real names, email addresses, last-login timestamps, and last accessed IP addresses, as well as a full backup of the Cadence server dating from 2024 containing credentials, configuration, artifacts, logs, or other sensitive information. The attack works by exploiting the deserialization of untrusted data vulnerability in TeamCity, allowing an attacker to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process. As a result, JetBrains is urging Cadence users to revoke and rotate all credentials following this security incident.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-63077 and treat internet-facing systems that were not patched in time as potentially compromised until verified. • Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

ap•••••.com
150.109.•••.•••
62.210.•••.•••
152.233.•••.•••
43.153.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-63077CVE-2026-63077
Target & Sectors
Global Scope
Incident Timeline
‎August 5, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the T1588.006 - Vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August 5, 2026.
attribution the Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
‎2026/08/06
Unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach JetBrains Cadence, extracting AWS credentials.
tactic Data Breach
organisation Data Breach / Identity Security
general_metric 05 Sep
‎August 8, 2026
Threat actors exploited unpatched TeamCity instances to gain access to JetBrains Cadence, subsequently extracting AWS credentials.
‎between August 8 and
Attackers breached JetBrains Cadence via unpatched TeamCity between August 8 and 24, 2026.
‎August 23, 2026
Threat actors exploited an unpatched TeamCity instance to breach JetBrains Cadence, extracting AWS credentials.
‎Sep 05, 2026
Threat actors exploited an unpatched vulnerability in JetBrains TeamCity to gain unauthorized access to a Cadence instance, allowing them to extract AWS credentials.
‎24, 2026
Attackers breached JetBrains Cadence via unpatched TeamCity between August 8 and 24, 2026.
‎2026/09/05
Threat actors exploited the unpatched TeamCity vulnerability (CVE-2026-63077) to breach JetBrains Cadence, extracting AWS credentials and accessing sensitive data.
organisation Unpatched TeamCity
organisation Extracting AWS
infrastructure 9.8
infrastructure 150.109.230
infrastructure 43.153.227
infrastructure 62.210.127
infrastructure 210.247.242
infrastructure 15.235.225
infrastructure 152.233.30
organisation Cadence IP
organisation Unexpected
organisation API
organisation SSH
organisation AWS
organisation Google Cloud Unexpected
organisation Cadence
organisation JetBrains
organisation IDE
organisation IP
organisation Multiple AWS IAM
organisation IAM
organisation S3
organisation JetBrains AWS
organisation Cadence JetBrains
organisation PyCharm
organisation the JetBrains Cadence
Tactical Metrics
Metrics
infrastructure
‎9.8
Software Version
Metrics
infrastructure
‎150.109.230
Software Version
Metrics
infrastructure
‎43.153.227
Software Version
Metrics
infrastructure
‎62.210.127
Software Version
Metrics
infrastructure
‎210.247.242
Software Version
Metrics
infrastructure
‎15.235.225
Software Version
Metrics
infrastructure
‎152.233.30
Software Version