Fetching from the wire…
Security2026-08-30 · source-backed
Attackers exploited CVE-2026-63077, the critical unauthenticated RCE in TeamCity On-Premises that JetBrains itself disclosed July 27, against an unpatched JetBrains-run server, reaching the Cadence cloud coding service. Because the PyCharm plugin syncs project files to Cadence before running them, customer source code, config files and embedded secrets may be exposed, along with usernames, real names, emails, last-login timestamps and last-accessed IPs. JetBrains is telling Cadence users to treat all prior executions and outputs as untrusted and rotate credentials across AWS, Azure, GCP, GitHub, GitLab, Bitbucket, npm, Maven, NuGet, PyPI, Docker Hub, ECR, GCR and ACR. (JetBrains) The uncomfortable part is the shape: cloud coding services need your source to run it, so a breach of the runner is a breach of everything it ran.
Each link below shares sources, entities, or timing with this story.
CVE-2026-33017 is an unauthenticated RCE (CVSS ~9.8) in Langflow's public flow-build endpoint. Attackers weaponized it within 20 hours of disclosure, before any public PoC, by reverse-engineering the advisory text. Exploitation systematically exfiltrated OpenAI, Anthropic, and...
GitHub shipped it July 28 across Pro through Enterprise, reachable from VS Code, Visual Studio, Copilot CLI, the cloud agent, JetBrains, Xcode, and Eclipse, with text and image inputs and low/medium/high reasoning effort, billed at provider list pricing rather than a fixed mul...
The Model Context Protocol has a security problem that's no longer theoretical — it's statistical. Between January and February 2026, researchers filed 30+ CVEs against MCP servers, clients, and infrastructure. One package with nearly 500,000 downloads carried a CVSS 9.6 RCE....
The sunset notice is short and it doesn't hedge. Code freeze July 29. Repository archived August 10. Core team gone August 31. npm and Docker packages deprecated. Flowise has 55,186 stars and 24,850 forks under Apache-2.0, and the team wrote its own cause of death: developers...
Hudson Rock got hold of the archive and counted it. 433,909 files. 118,829 CI runner dumps traced to 2,488 corporate domains. AWS keys, Salesforce client secrets, Slack signing secrets, Azure environment variables, and AI provider API keys belonging to NVIDIA, Volkswagen, Micr...
Microsoft and GitHub disabled the repos, many of them Azure and AI developer tools, after attackers injected malware that harvests credentials the moment a repo is opened in Claude Code, Gemini CLI, or VS Code. Miasma is built on the open-sourced Mini Shai-Hulud codebase from...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.