Wire Observer.
Technology

JetBrains Urges Cadence Users to Revoke AWS Keys After TeamCity Exploit

JetBrains Urges Cadence Users to Revoke AWS Keys After TeamCity Exploit

JetBrains has issued an urgent advisory to users of its Cadence workflow automation platform, recommending that all stored credentials be revoked and regenerated following a security breach discovered last month. The intrusion was traced to a critical flaw in the company’s TeamCity continuous integration tool, which attackers leveraged to gain unauthorized access to JetBrains' internal systems and extract Amazon Web Services (AWS) keys.

The vulnerability in TeamCity, disclosed publicly just weeks before the incident, was classified as critical and required immediate patching. JetBrains acknowledges that the affected TeamCity instances were not updated in time, allowing threat actors to exploit the flaw and move laterally into the environment that hosts Cadence services. By obtaining AWS credentials, the attackers potentially gained the ability to read, modify, or delete resources in the cloud accounts linked to Cadence deployments.

JetBrains has not identified the individuals or groups behind the attack, nor has it confirmed whether any data beyond the AWS keys was accessed or exfiltrated. The company’s statement emphasizes that the breach was confined to the internal infrastructure used to support Cadence, and that no direct compromise of end‑user Cadence projects has been observed. Nonetheless, the exposure of cloud credentials poses a significant risk, prompting the call for immediate credential rotation.

Security experts note that the incident underscores the broader challenge of maintaining a rapid patching cadence for development tools that are integral to modern software pipelines. TeamCity, like many CI/CD platforms, often runs with elevated privileges and deep integration with cloud services, making any unaddressed flaw a high‑value target. Organizations are advised to adopt a layered defense strategy, including regular vulnerability scanning, timely application of security updates, and the use of short‑lived, scoped credentials wherever possible.

For Cadence users, JetBrains recommends revoking all existing AWS access keys associated with the platform, generating new ones, and updating any configuration files or secret management systems accordingly. The company also suggests reviewing IAM policies to ensure that permissions follow the principle of least privilege, limiting the potential impact of any future credential leakage.

Looking ahead, JetBrains says it is conducting a thorough forensic investigation and will release further details as they become available. The incident serves as a reminder that even well‑known development toolchains can become vectors for supply‑chain attacks, reinforcing the need for continuous security hygiene across the software development lifecycle.

Source: feedburner
Aarav Mehta — Technology desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related