Tag

Atlassian Confluence

All articles tagged with #atlassian confluence

Persistent 'Effluence' Backdoor Exploited in Widespread Atlassian Confluence Attacks
cyber-attack-threat-intelligence2 years ago

Persistent 'Effluence' Backdoor Exploited in Widespread Atlassian Confluence Attacks

A stealthy backdoor named Effluence has been discovered by cybersecurity researchers, persisting despite patching Atlassian Confluence servers. The backdoor allows for lateral movement to other network resources and data exfiltration from Confluence, and can be accessed remotely without authentication. The attack chain involves exploiting critical vulnerabilities in Atlassian Confluence, including CVE-2023-22515 and CVE-2023-22518, which allow for unauthorized administrator account creation and complete loss of confidentiality, integrity, and availability. The attacker gains initial access through CVE-2023-22515 and embeds a web shell that grants persistent remote access to every web page on the server. The web shell's loader component acts as a normal Confluence plugin, while the payload component executes malicious actions. The backdoor is potentially applicable to other Atlassian products as well.

"Critical Security Alert: Patch Atlassian Confluence Now, Warns CISA and FBI"
cybersecurity2 years ago

"Critical Security Alert: Patch Atlassian Confluence Now, Warns CISA and FBI"

CISA, FBI, and MS-ISAC have issued a warning to network administrators to immediately patch their Atlassian Confluence servers against a critical privilege escalation flaw (CVE-2023-22515) that is actively being exploited in attacks. The flaw affects Confluence Data Center and Server 8.0.0 and later versions and can be remotely exploited without user interaction. Atlassian had previously advised customers to upgrade their instances or isolate them if upgrading was not possible. The organizations also encourage organizations to hunt for malicious activity and apply incident response recommendations. While exploitation has been limited so far, the ease of exploitation is expected to lead to widespread attacks on unpatched Confluence instances.