Security & Threat Intelligence

The Watch

The Signal

JetBrains' own TeamCity breach likely exposed Cadence customers' credentials and code.

No patch applies, because the compromised system was the vendor's, not yours. JetBrains' own assessment is that customer source code and credentials held in Cadence were likely stolen, which makes your credential inventory the incident scope and August's cloud authentication logs the place the answer lives.

In Play

  1. Two Remote-Management Platforms, One Change Window

    N-able shipped a severity-10 pre-authentication RCE in N-central, one month after a separate N-central zero-day, per Risky Business. ConnectWise disclosed a ScreenConnect remote-access flaw with the CVE and patch still pending. Compromise of either console means SYSTEM-level access on every endpoint it manages. SANS NewsBites adds SonicWall SMA1000: an exploited pre-auth flaw scoring 10.0, no workaround, and a federal KEV deadline that lapsed September 5.

  2. JetBrains Was Breached Through Its Own TeamCity

    JetBrains was compromised via a vulnerability in its own TeamCity servers, and the intrusion reached Cadence, its cloud LLM training platform, per Risky Business. The vendor's own assessment is that customer source code and credentials stored there were likely stolen. No patch helps here, so the only control is rotating every secret Cadence ever held. Your credential inventory is the incident scope, and cloud authentication logs from August need a sweep.

  3. Cyber Capability Became the Release Gate

    OpenAI's GPT-6 Astra scored 100% on ExploitBench and found two previously unknown vulnerabilities on its own during pre-release testing. Google shipped Gemini 3.8 Flash Cyber under restricted access for vulnerability discovery, then credited that cyber training for reasoning gains in the general model anyone can buy. Your 30-day critical tier is priced on a disclosure-to-weaponization lag that is shrinking. Independent Artificial Analysis testing rates Astra near its predecessor, so the magnitude is contested.

  4. €35M Moved Through Edited Records, Not Spoofed Email

    A four-year campaign moved €35M through more than 500 French notary offices, roughly 7% of the sector, without spoofing a single email, per Risky Business. Attackers phished in, took over networks, then quietly altered transaction details inside the systems of record. Procedural checks banks added in 2024 did not stop the losses. If your payment master data carries no immutable change audit, a valid-credential edit surfaces only when the bank flags it.

  5. Your Compute Vendors Are Becoming ICS Operators

    The NAACP sued xAI in April 2026, alleging 27 gas turbines rated at least 495 MW ran without a required air permit at its Southaven, Mississippi site. Behind-the-meter generation turns a compute provider into an industrial control system operator, and turbine controllers and switchgear sit outside every SOC 2 report you collect. Ireland's regulator says data-center demand outpaces network delivery at 23% of metered electricity, so a court order or connection moratorium is an availability event with no failover.

Deep Dives

  1. Four Critical Flaws, and Patching Is Not the Control on Any of Them

    What actually applies is network reachability and credential invalidation, and both live with teams that do not run the patch queue.

    Patching an exploited appliance does not evict the operator Citrix fixed CVE-2026-19490 in August. Previdian reports in-the-wild exploitation of that auth-bypass-with-command-execution chain. Any NetScaler that missed the August window has been reachable ever since, so patching today closes the door…

    3 action items

  2. The Exploit Clock Sped Up and Nobody Has Timed Your Pipeline

    Three labs put cyber capability behind the release gate; the gap it exposes on your side is not detection quality but the unmeasured minutes between a fix existing and a fix running.

    The gate is on the branded product, not on the capability OpenAI gates GPT-6 Astra behind a vetted program called Daybreak . Standard access refuses exploit work, so the refusal lands on internal red teams, AppSec fuzzing pipelines and pentest…

    3 action items

  3. €35M Left Through Edited Records, and the Bank Checks Did Not Catch It

    The mitigations that worked in France were structural, the downstream approval steps added midway through the fraud were not, and that difference tells you exactly where to spend.

    Start with what failed Banks added extra procedural checks in 2024. The fraudulent transfers continued. That detail is the most useful thing in the case, because it invalidates the control most organizations lean on. Downstream approval cannot detect an attacker…

    3 action items

The edition continues

Take the signal into the room.

Sign up or log in to read all 3 deep dives in full, plus the final take.

Read the full edition

Continue with LinkedIn