JetBrains Cadence Service Compromised Through Unpatched TeamCity Server

This title was summarized by AI from the post below.

JetBrains disclosed that its hosted Cadence service was compromised through an unpatched TeamCity server running a vulnerability the company itself published on July 27 and warned customers was being exploited on August 7 — and stated plainly that the server should have been patched as part of its own response but was not. Attacker activity began August 8, was discovered August 23, and the server was taken offline August 24, with confirmed extraction of usernames, real names, email addresses, last-login timestamps, and last-accessed IP addresses, plus compromise of a full 2024 server backup whose credentials, configuration, artifacts, and logs must all be treated as exposed. Users are told to treat any secret stored in Cadence, contained in that backup, or used during an execution as compromised — cloud provider credentials, Git host tokens, package registry keys, SSH and deployment keys, service account credentials, signing keys — and to hunt for unexpected repository clones, unexpected commits, and changes to repository secrets, webhooks, collaborators, or permissions from August 8 onward. #DevSecOps #SupplyChainSecurity #IncidentResponse #PatchManagement #Cybersecurity https://lnkd.in/g6RihZ9w

To view or add a comment, sign in

Explore content categories