A severe security breach at JetBrains affected its Cadence server, enabling attackers to exploit an unpatched vulnerability (CVE-2026-63077) in TeamCity. From August 8 to August 24, 2026, the attackers accessed sensitive cloud infrastructure, personal user information, and a complete Cadence backup. This exposure included critical AWS IAM credentials and access to proprietary project data across various platforms like GitHub and npm.
JetBrains acknowledged the failure to install a crucial security patch, emphasizing the increased risk posed by compromising developer infrastructure. The company is currently investigating the breach and advising affected users to revoke any compromised credentials.