Key Facts

JetBrains has urged Cadence users to revoke or rotate credentials and secrets that may have been used for Cadence executions after a security incident.

Technical Details

Published incident coverage reports that attackers exploited a TeamCity vulnerability to access Cadence data, including a 2024 server backup, and that JetBrains took the affected server offline.

Impact & Mitigation

Rotate Cadence-related credentials, review cloud accounts, storage, repositories, package registries, and deployment environments for suspicious activity, and treat affected execution inputs and outputs as untrusted.

Sources

By Allan