Skip to main content

Attackers Use Public Exploits to Throttle Atlassian Confluence Flaw


Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

 

June 7,  2022  By Elizabeth Montalbano

 

The vulnerability remains unpatched on many versions of the collaboration tool and has potential to create a SolarWinds-type scenario.

Threat actors are using public exploits to pummel a critical zero-day remote code execution (RCE) flaw that affects all versions of a popular collaboration tool used in cloud and hybrid server environments and allows for complete host takeover.

Researchers from Volexity uncovered the flaw in Atlassian Confluence Server and Data Center software over the Memorial Day weekend after they detected suspicious activity on two internet-facing web servers belonging to a customer running the software, they said in a blog post published last week.

 

>> Full Article <<

0 replies

Be the first to reply!

Reply