Key Facts
JetBrains has urged Cadence users to revoke or rotate credentials and secrets that may have been used for Cadence executions after a security incident.
Technical Details
Published incident coverage reports that attackers exploited a TeamCity vulnerability to access Cadence data, including a 2024 server backup, and that JetBrains took the affected server offline.
Impact & Mitigation
Rotate Cadence-related credentials, review cloud accounts, storage, repositories, package registries, and deployment environments for suspicious activity, and treat affected execution inputs and outputs as untrusted.
