Executive Summary
Between August 8 and August 24, 2026, JetBrains Cadence, a hosted cloud compute service for PyCharm, was compromised by unknown threat actors. The attackers exploited CVE-2026-63077, a critical vulnerability in the underlying TeamCity orchestration engine that allows unauthenticated remote command execution.
The investigation confirmed that the adversary accessed a full server backup from 2024 and potentially the current production environment. Impacted data includes project source code, customer email addresses, real names, last-login metadata, and sensitive credentials including AWS IAM keys and S3 bucket contents. JetBrains has taken the affected API endpoint offline and invalidated plugin access tokens.
This incident represents a significant risk to organizations utilizing Cadence for automated workflows, as exposed credentials could facilitate lateral movement into customer-owned AWS, GitHub, or package registry environments. Immediate rotation of all secrets used within the service is required.
