| ~7 MIN READ |
| FACT | An autonomous AI agent framework assembled by hackers in under six hours stole thousands of employee credentials with no human operator after setup. A speed no human team could match. (Google Threat Intelligence Group Q3 2026 AI Threat Tracker) |
The perimeter is still shrinking, and this edition has a specific thread: the systems you outsourced trust to are failing in the ordinary spots. A skipped patch. A delayed disclosure. An unmonitored standalone box. Attackers found all three. PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe → |
Developer tools 🔧 JetBrains Got Hacked Through a Bug in JetBrains. The Credentials Your Pipeline Was Storing Are Gone. Intro The company that distributes the developer tools your team trusts just proved it doesn’t always apply its own security patches. What Happened Between August 8 and August 24, attackers exploited CVE-2026-63077, a critical unpatched TeamCity vulnerability, to breach Cadence, JetBrains’ own cloud compute service. They exfiltrated AWS IAM credentials, PyCharm project source code, S3 bucket contents, and a full 2024 server backup. JetBrains acknowledged the compromised server “should have been patched as part of its own vulnerability response efforts” but offered no explanation for why it wasn’t. Why It Matters AWS IAM credentials are skeleton keys. Anyone who used Cadence during that window should treat their cloud environment as potentially accessed. Supply-chain attacks begin exactly like this: a trusted tooling vendor gets breached, and the real target is everyone downstream. The Other Side JetBrains says the breach was limited to a defined group of Cadence users with no broader system impact. No downstream customer breaches have been confirmed yet.
TL;DR: JetBrains didn’t patch its own product inside its own cloud. Attackers walked in, and AWS credentials and source code left with them. Further reading: The Hacker News |
AI can build faster. Can your team decide better?
AI can draft the PRD and prototype the idea. Jira Product Discovery helps teams decide whether it belongs on the roadmap. Bring feedback and ideas together, prioritize as a team, and keep your roadmap connected to delivery in Jira.
|
Blu Dot surpasses 2,000% ROAS with self-serve CTV ads
Home furniture brand Blu Dot blew up on CTV with help from Roku Ads Manager. Here’s how:
After a test campaign reached 211,000 households and achieved 1,010% ROAS, the brand went all in to promote its annual sales event. It removed age and income constraints to expand reach and shifted budget to custom audiences and retargeting, where intent was strongest.
The results speak for themselves. As Blu Dot increased their investment by 10x, ROAS jumped to 2,308% and more page-view conversions surpassed 50,000.
“For CTV campaigns, Roku has been a top performer,” said Claire Folkestad, Paid Media Strategist, Blu Dot. “Comping to our other platforms, we have seen really strong ROAS… and highly efficient CPMs, lower than any other CTV partner we've worked with.”
Using Roku Ads Manager, the campaign moved from a pilot to a permanent performance engine for the brand.
|
|
|
![]() Strange but real 🚔 Qilin Ransomware Hacked the Federal Agency That Investigates Criminal Networks. Then Published the Files. Intro Qilin ransomware hit the Bureau of Alcohol, Tobacco, Firearms and Explosives. The ATF confirms it. The DOJ formally classified it a “major incident,” which requires mandatory notification to Congress. What Happened Qilin breached a standalone ATF system containing information on the agency’s active investigation targets. After the ATF declined to negotiate, the group published the files: phone extractions from criminal investigations, field office documents. The ATF says the system was isolated and shut down immediately after discovery. Why It Matters When investigation files go public, the harm goes beyond embarrassment. Witnesses, informants, and ongoing case strategies may now be visible to the networks those investigations were targeting, which can disrupt active law enforcement operations rather than just leaking data. The Other Side The ATF says the compromised system wasn’t connected to any other ATF infrastructure and that operational capability hasn’t been affected. No broader mission compromise has been confirmed.
TL;DR: Qilin hacked the ATF, published its investigation files, and the people under active federal investigation may now know what the ATF had on them. Further reading: SecurityWeek |
Smarter CRM. Less Busywork.
Disconnected data and tools make it harder to understand your customers. HubSpot's Agentic Customer Platform brings your data, teams, and tech stack together with AI built in to help your business work faster and create more personalized customer experiences.
Why HubSpot and what's new
Use AI powered tools to take action faster
Unify your data, teams, and tech stack in one place
Create one shared view of customer data
Connect teams around the same customer context
Bring your business tools into one place
Connect more of your business in one place and give every team a smarter way to work. Get set up quickly and start checking off your hardest tasks.





