Unpatched TeamCity Flaw Exposes JetBrains Cloud to AWS Credential Theft
Attackers exploited a critical, unpatched vulnerability (CVE-2026-63077) in JetBrains' own TeamCity instance — a particularly damaging irony given TeamCity is a CI/CD product used widely in software pipelines. By gaining a foothold through the unpatched server, adversaries accessed a 2024 backup containing AWS IAM credentials, meaning a single missed patch cascaded into potential exposure of source code, user data, and cloud infrastructure. Long-lived, overly permissive IAM credentials stored within backup artifacts dramatically amplified the blast radius of the initial compromise. This incident underscores that even security-savvy software vendors must apply their own tools' patches with urgency, and that credentials must never be allowed to persist indefinitely in backup stores.
Tactical Insight
Immediate actions
- Patch or upgrade all TeamCity instances to the latest version and audit all other internet-facing CI/CD systems for unresolved CVEs.
- Revoke, rotate, and audit all AWS IAM credentials that may have been exposed in backup files or pipeline configurations.
- Scan all backup archives and source repositories for embedded secrets using tools such as AWS Macie, truffleHog, or GitLeaks.
Long-term improvements
- Enforce a secrets management policy requiring all credentials (AWS, API keys, tokens) to be stored exclusively in a dedicated vault (e.g., HashiCorp Vault, AWS Secrets Manager) and never in backup files or config artifacts.
- Implement least-privilege IAM policies with time-bound, role-based access so that any extracted credential has minimal usable scope.
- Establish an emergency patching SLA (e.g., 24–48 hours) for critical-severity CVEs affecting internet-exposed infrastructure, enforced via change management processes.
Detection measures
- Enable AWS CloudTrail and GuardDuty to detect anomalous IAM credential usage patterns, such as access from unexpected geographies or IPs.
- Deploy continuous vulnerability scanning (e.g., Tenable, Qualys) against all production and staging CI/CD assets with alerting on newly published critical CVEs.
- Implement integrity monitoring on backup artifacts to detect unauthorized access or exfiltration attempts.