JetBrains confirms its Cadence cloud service was breached through a TeamCity vulnerability it had itself disclosed. CVE-2026-63077 is critical: unauthenticated attackers could run commands on it. Cadence stayed unpatched, and attackers were inside from 8 to 24 August.
Their own sentence: "The server should have been patched as part of our response to the vulnerability, but it was not."
The exposure is what build infrastructure concentrates: a full 2024 server backup, multiple AWS IAM credentials, potentially source code synced from developers' machines. Everything in reach now needs rotating.
Two lessons travel. CI/CD is crown jewels, not plumbing. The patch that counts is the one verified applied, on your estate as much as a supplier's.
https://blog.jetbrains.com/pycharm/2026/08/cadence-security-incident-august-2026/
#SupplyChainSecurity #InfoSec #CyberSecurity
Remote
Adrian Hollister
@adrianhollister@infosec.exchange
Director of IT & Cyber Security and DPO in international development. Writing The Sovereignty Papers: European digital sovereignty, AI governance, and where the human sits in AI-heavy work. Founder of AltLibre. Neurodivergent; published on AI as a communication bridge between neurodivergent and neurotypical people. Cornwall, on the edge of Bodmin Moor. Views my own.
4 Followers
10 Following
5 Posts
Joined August 26, 2026
AltLibre:
Based:
Cornwall, UK
Open post
China’s spy chief just put the world on notice about AI. Chen Yixin warns foreign powers are using genAI to fabricate rumours, launch opinion wars, and hack. He singled out Claude Mythos and ChatGPT-5.5-Cyber. This is tech sovereignty. Xi-Trump meeting next. The race is on. Are we ready?
0
0
0
0
Open post
ENISA's 2026 Threat Landscape is out. Two numbers belong together. Where ENISA could identify the intrusion vector, 60% of unauthorised-access incidents came through a vulnerability, N-day or zero-day. And 2025 published over 48,000 new CVEs, up 22% on the year before. More doors, and the doors are the preferred route in. The other thread is dependencies. Supply-chain and third-party attacks are what produce the large-scale incidents. Which is why the point about patch clocks shrinking to days is not pedantry. The patch programme and the supplier register are the same control now.
https://www.enisa.europa.eu/news/exploring-the-evolution-of-the-cyber-threat-landscape-how-dependencies-weaken-our-digital-resilience
#CyberSecurity #InfoSec #ENISA #DigitalSovereignty
0
0
0
0
Open post
The first control in the CIS list is not a firewall or a password rule. It is knowing what you have. Inventory and control of enterprise assets, including the cloud ones, including the ones nobody bought on purpose.
Every framework starts there because everything else stands on it. You cannot patch the server nobody recorded. You cannot put the unlisted laptop in the risk register. Unmanaged and unknown are the same thing to an attacker.
The failure mode I keep meeting is the inventory that lives in a spreadsheet someone updates quarterly. The fix is unglamorous: discovery that runs continuously, from the network and the cloud accounts themselves, not declarations collected by email. What connects tells you the truth. What people remember does not.
https://www.cisecurity.org/controls/inventory-and-control-of-enterprise-assets
#CyberSecurity #InfoSec #AssetManagement
0
0
0
0
Open post
MFA is on the checklist of every audit I have ever seen, and the tick is where most thinking stops. It should not be. The NCSC's guidance is blunt about it: not all types of MFA are created equal.
Text messages can be intercepted. A bare push notification can be spammed until someone taps approve at 11pm to make it stop. That is MFA fatigue, and it works because the approval asks nothing of the user except irritation.
The better versions make phishing structurally harder: number matching, so the person must see the login screen to approve it, and passkeys or hardware keys, where there is no code to type into a fake page at all. If your MFA rollout ended at "any second factor counts", the project is not finished. The factor you chose is the control.
https://www.ncsc.gov.uk/guidance/multi-factor-authentication-online-services
#CyberSecurity #InfoSec #MFA
0
0
0
0