JetBrains confirms its Cadence cloud service was breached through a TeamCity vulnerability it had itself disclosed. CVE-2026-63077 is critical: unauthenticated attackers could run commands on it. Cadence stayed unpatched, and attackers were inside from 8 to 24 August.
Their own sentence: "The server should have been patched as part of our response to the vulnerability, but it was not."
The exposure is what build infrastructure concentrates: a full 2024 server backup, multiple AWS IAM credentials, potentially source code synced from developers' machines. Everything in reach now needs rotating.
Two lessons travel. CI/CD is crown jewels, not plumbing. The patch that counts is the one verified applied, on your estate as much as a supplier's.
https://blog.jetbrains.com/pycharm/2026/08/cadence-security-incident-august-2026/
#SupplyChainSecurity #InfoSec #CyberSecurity
Remote
Adrian Hollister
@adrianhollister@infosec.exchange
Director of IT & Cyber Security and DPO in international development. Writing The Sovereignty Papers: European digital sovereignty, AI governance, and where the human sits in AI-heavy work. Founder of AltLibre. Neurodivergent; published on AI as a communication bridge between neurodivergent and neurotypical people. Cornwall, on the edge of Bodmin Moor. Views my own.
0 Followers
0 Following
2 Posts
Joined August 26, 2026
AltLibre:
Based:
Cornwall, UK
Open post
China’s spy chief just put the world on notice about AI. Chen Yixin warns foreign powers are using genAI to fabricate rumours, launch opinion wars, and hack. He singled out Claude Mythos and ChatGPT-5.5-Cyber. This is tech sovereignty. Xi-Trump meeting next. The race is on. Are we ready?
0
0
0
0