daily cyber × ai intelligence

index

tagged

[cadence]

1 edition · 1 item

September 7, 2026

  • JetBrains is telling Cadence users to revoke and rotate every credential and secret and to treat all executions, inputs and outputs as untrusted, after attackers exploited CVE-2026-63077 (CVSS 9.8, deserialization to unauthenticated OS command execution) against a TeamCity server in JetBrains' own environment. The flaw has been in CISA's KEV catalog since 5 August; JetBrains discovered the intrusion on 23 August. The actor reached a 2024 Cadence backup and storage containing current-user data — usernames, real names, email addresses, last-login timestamps and last-accessed IPs, project source code and credentials — and defenders should hunt authentication activity using Cadence-stored credentials from 8 August onward (The Hacker News). · CI/CD & Identity

in The Diff Is the Disclosure: MikroTik's Silent Patch Comes Apart