Back to all lessons
Awareness Lessons
last month

Unpatched TeamCity Flaw Exposes JetBrains Cloud to AWS Credential Theft

Attackers exploited a critical, unpatched vulnerability (CVE-2026-63077) in JetBrains' own TeamCity instance — a particularly damaging irony given TeamCity is a CI/CD product used widely in software pipelines. By gaining a foothold through the unpatched server, adversaries accessed a 2024 backup containing AWS IAM credentials, meaning a single missed patch cascaded into potential exposure of source code, user data, and cloud infrastructure. Long-lived, overly permissive IAM credentials stored within backup artifacts dramatically amplified the blast radius of the initial compromise. This incident underscores that even security-savvy software vendors must apply their own tools' patches with urgency, and that credentials must never be allowed to persist indefinitely in backup stores.

Tactical Insight

Immediate actions

  • Patch or upgrade all TeamCity instances to the latest version and audit all other internet-facing CI/CD systems for unresolved CVEs.
  • Revoke, rotate, and audit all AWS IAM credentials that may have been exposed in backup files or pipeline configurations.
  • Scan all backup archives and source repositories for embedded secrets using tools such as AWS Macie, truffleHog, or GitLeaks.

Long-term improvements

  • Enforce a secrets management policy requiring all credentials (AWS, API keys, tokens) to be stored exclusively in a dedicated vault (e.g., HashiCorp Vault, AWS Secrets Manager) and never in backup files or config artifacts.
  • Implement least-privilege IAM policies with time-bound, role-based access so that any extracted credential has minimal usable scope.
  • Establish an emergency patching SLA (e.g., 24–48 hours) for critical-severity CVEs affecting internet-exposed infrastructure, enforced via change management processes.

Detection measures

  • Enable AWS CloudTrail and GuardDuty to detect anomalous IAM credential usage patterns, such as access from unexpected geographies or IPs.
  • Deploy continuous vulnerability scanning (e.g., Tenable, Qualys) against all production and staging CI/CD assets with alerting on newly published critical CVEs.
  • Implement integrity monitoring on backup artifacts to detect unauthorized access or exfiltration attempts.