JetBrains Cadence breached through an unpatched TeamCity flaw, AWS IAM credentials exfiltrated
Attackers exploited CVE-2026-63077 (CVSS 9.8) to break into Cadence, JetBrains’ cloud GPU service, between August 8 and 24, 2026, exfiltrating AWS IAM credentials and data held in S3 buckets. Revoke and rotate every credential and secret tied to Cadence without delay.