Threat Brief — 2026-09-05 — Supply-chain fallout and blockchain-hosted payloads
Executive summary. Four stories broke today, headlined by a confirmed breach of JetBrains' own Cadence environment through an unpatched TeamCity server — attackers extracted AWS credentials, prompting urgent rotation guidance. Separately, a large-scale ClickFix operation has weaponised BNB Smart Chain smart contracts to host payloads delivered via 5,400+ compromised websites. Broadcom patched a critical VMware Workstation/Fusion flaw enabling host code execution from a VM, and Trezor disclosed an additional 67,000 U.S. customer records exposed via its ShipMonk shipping provider.
Top items
- JetBrains Cadence breached via unpatched TeamCity — AWS credentials stolen. Attackers exploited a known critical TeamCity deserialization vulnerability to compromise JetBrains' own Cadence environment and extract AWS credentials. JetBrains is urging all Cadence users to revoke and rotate credentials immediately. This is a developing story: the TeamCity CVE was first reported on 2026-08-05 via CISA's Known Exploited Vulnerability catalog, and today's confirmation that JetBrains' own infrastructure was breached — with AWS credential theft — marks a significant escalation. (src: The Hacker News)
- Critical VMware Workstation/Fusion flaw enables VM-to-host code execution. Broadcom released patches for a critical vulnerability in VMware Workstation and Fusion that could allow a malicious VM administrator to execute arbitrary code on the host system under certain conditions. The attack requires existing administrative access inside a guest VM, limiting the blast radius, but any environment where untrusted users control VMs is at risk. This story was first reported earlier today. (src: The Hacker News)
- ClickFix payloads hosted on BNB Smart Chain, served via 5,400+ compromised sites. A criminal operation is storing malicious ClickFix payloads inside smart contracts on BNB Smart Chain (BSC), then delivering them through thousands of compromised small-business websites. Blockchain-based hosting gives attackers a persistent, takedown-resistant delivery channel — once written to a smart contract, the payload cannot be unilaterally removed. This story was first reported earlier today. (src: BleepingComputer)
- Trezor ShipMonk breach expands to 67,000 additional U.S. customer records. Hardware wallet maker Trezor disclosed that a further 67,000 U.S. customers are affected by the ShipMonk shipping-provider breach, with exposed data including names, email addresses, and phone numbers. Trezor states this data was previously believed deleted. This story was first reported earlier today. (src: The Hacker News)
Themes
Supply-chain and third-party trust failures dominate. Two of today's four items — JetBrains' own infrastructure breached through its flagship CI/CD product, and Trezor's customer data compromised via a shipping provider — illustrate how trusted vendor ecosystems become attack surfaces. The JetBrains incident is particularly notable as a case of a vendor being exploited through its own product, with cloud credential theft as the outcome. Meanwhile, the ClickFix campaign's use of blockchain smart contracts for payload hosting represents an evolution in infrastructure resilience that will complicate takedown efforts.
===
