JetBrains Calls for Credential Reset After TeamCity Exploit Hits Cadence Platform
JetBrains, the maker of the Cadence continuous integration and delivery suite, has warned all Cadence customers to immediately revoke and replace any credentials that may have been compromised after a breach that occurred last month.
According to the company, the intrusion was carried out by unknown attackers who leveraged a critical vulnerability in TeamCity, JetBrains' own build automation server, that had been publicly disclosed only weeks before the incident. The flaw, rated critical, allowed the threat actors to gain unauthorized access to JetBrains' internal network where the Cadence service is hosted.
Once inside, the attackers extracted Amazon Web Services (AWS) access keys used by Cadence to orchestrate build jobs and store artefacts. The stolen credentials could potentially enable malicious actors to spin up resources, access stored code, or exfiltrate data from any Cadence‑managed project that relies on those keys.
JetBrains' advisory urges users to treat the situation as a credential‑compromise event. It recommends that all Cadence users generate new AWS keys, update any related IAM policies, and audit recent activity for signs of unauthorised use. The company also says it has patched the TeamCity vulnerability across its services and is reviewing its internal security controls to prevent future exploitation.
Security experts note that supply‑chain attacks of this nature—where a breach of a software vendor’s own tools is used to reach downstream customers—highlight the importance of layered defenses. Regular credential rotation, the principle of least privilege, and monitoring for anomalous cloud activity are widely‑advised safeguards that can limit the damage of such breaches.
The incident underscores the broader challenge of maintaining security in complex CI/CD ecosystems, where multiple tools interconnect and share access tokens. As organizations continue to adopt automation for software delivery, the need for rigorous patch management and rapid response to newly disclosed vulnerabilities becomes ever more critical.
JetBrains has pledged to keep the community informed of any further developments and to provide detailed guidance on hardening Cadence deployments. Customers are advised to stay in contact with their account representatives and to review the company's security bulletin for the latest recommendations.
Comments (0)
Be the first to comment.
Join the discussion