JetBrains Cadence user data exposure from 2024 backup
Data Leak
Summary
Hide ▲
Show ▼
JetBrains Cadence user data from a 2024 server backup was accessed during the August 2026 intrusion, putting credentials, project source code, and other stored records at risk of exposure. JetBrains said attackers reached data tied to current Cadence users and treated the stored material as potentially exposed. The company also invalidated Cadence plugin access tokens and told users to revoke or rotate all credentials. The exposure raises immediate risk of account abuse and follow-on phishing using the affected contact data.
Related Happenings
FortiBleed Fortinet/FortiGate VPN credential leak
Data Leak
H score80
First: 17.06.2026 18:12
Last: 17.06.2026 18:12
Sources 1
About this happening:
FortiBleed is a data leak of Fortinet/FortiGate VPN credentials that now includes a verified database of 86,644 confirmed working credentials collected from inte...
FortiBleed Fortinet/FortiGate VPN credential leak
Data LeakAbout this happening: FortiBleed is a data leak of Fortinet/FortiGate VPN credentials that now includes a verified database of 86,644 confirmed working credentials collected from inte...
Latest development: 19.06.2026 09:47
CISA urged Fortinet customers to secure FortiGate appliances after nearly 74,000 firewall and VPN credentials were exposed in the FortiBleed leak. The agency advised affected owners to terminate SSL VPN and administrative sessions, reset VPN and administrative passwords, enable phishing-resistant multifactor authentication, review logs for unauthorized access or lateral movement, store admin credentials with PBKDF2, restrict firewall management interfaces from public internet access, and remove unauthorized accounts.
Timeline
-
05.09.2026 19:52 1 articles · 1h ago
CISA adds CVE-2026-63077 to the KEV catalog
Industry Or Public Sector UpdateCISA adds CVE-2026-63077 to the Known Exploited Vulnerabilities catalog for the TeamCity deserialization flaw.
Show sources
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials — thehackernews.com — 05.09.2026 19:52
-
05.09.2026 19:52 1 articles · 1h ago
JetBrains discovers exploitation of CVE-2026-63077 against Cadence
Exploitation ObservedJetBrains discovers exploitation of CVE-2026-63077 on August 23, 2026 after the TeamCity flaw was used to breach Cadence environments.
Show sources
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials — thehackernews.com — 05.09.2026 19:52
-
05.09.2026 19:52 2 articles · 1h ago
JetBrains urges Cadence users to revoke credentials after backup exposure
Initial DisclosureJetBrains tells Cadence users to revoke or rotate all credentials and treat executions as untrusted after unidentified threat actors accessed a 2024 Cadence server backup and data tied to current users, including email addresses, project source code, and credentials.
Show sources
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials — thehackernews.com — 05.09.2026 19:52
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials — thehackernews.com — 05.09.2026 19:52