Monday, 24 February 2025
25.8 C
Singapore
28.3 C
Thailand
19.8 C
Indonesia
25.6 C
Philippines

Microsoft alerts on nation-state hackers exploiting Atlassian Confluence vulnerability

Microsoft identifies a critical Atlassian Confluence vulnerability exploited by nation-state actor Storm-0062, urging companies to update their software to mitigate risks.

Microsoft has identified a severe vulnerability in the Atlassian Confluence Data Center and Server, which, it says, has been exploited by a nation-state entity known as Storm-0062 (also referred to as DarkShadow or Oro0lxy).

According to Microsoft’s threat intelligence crew, the exploit has been observed in action since September 14, 2023.

The vulnerability, labelled as CVE-2023-22515, is described as a critical privilege escalation flaw within Atlassian’s Confluence Data Center and Server. This flaw could be exploited if a device is network-connected to a susceptible application, allowing the perpetrator to create an administrator account within the Confluence application.

The cybersecurity implications

CVE-2023-22515, with a maximum severity score of 10.0 on the CVSS scale, enables remote attackers to fabricate unauthorized administrator accounts and gain access to Confluence servers. Atlassian has released patches for this flaw in its versions 8.3.3, 8.4.3 and 8.5.2 (Long Term Support release) or later.

The exact extent of the attacks remains unclear. Still, Atlassian became aware of the issue through reports from a few customers, indicating that the threat actor exploited this vulnerability as a zero-day.

Notably, Oro0lxy is a digital pseudonym used by Li Xiaoyu, a hacker from China who, as per the U.S. Department of Justice (DoJ) allegations in July 2020, infiltrated numerous companies across the U.S., Hong Kong, and China, Moderna – a coronavirus vaccine research developer, being among them.

Xiaoyu is believed to be associated with the Guangdong regional division of China’s Ministry of State Security (MSS), operated at times for personal financial gain and at others for the advantage of MSS or other Chinese government entities, as per the DoJ. The DoJ described the hacking activities as a significant and sophisticated threat involving the theft of terabytes of data from U.S. networks.

Companies using Confluence applications are strongly advised to update to the newest versions to lessen the risks and to keep these applications off the public internet until the remedial measures are implemented.

Hot this week

Nothing Phone 3A and 3A Pro leaks show complete design and key specs

Leaked videos and images reveal the Nothing Phone 3A and 3A Pro, showing full designs, key specs, AI features, and camera details before launch.

OPPO unveils Find N5: The worldโ€™s thinnest foldable phone with cutting-edge AI and battery life

OPPO launches Find N5, the world's thinnest foldable phone, featuring advanced AI, the largest inner screen, industry-best battery life, and powerful cameras.

Apple may launch a 27-inch Mini LED Studio Display this year

Apple might refresh its Studio Display with a 27-inch Mini LED version later this year, offering better performance and contrast.

Nvidia acknowledges RTX 5090 and 5070 Ti manufacturing defect

Nvidia confirms a rare manufacturing defect in the RTX 5090 and 5070 Ti, affecting less than 0.5% of GPUs. Affected users can request a replacement.

HP acquires Humane for US$116 million, sparking job offers and layoffs

HP acquired an AI startup called Humane for US$116M, offering big pay raises to some employees while suddenly laying off others in a company shake-up.

Did xAI mislead the public about Grok 3โ€™s benchmarks?

xAI is under scrutiny for allegedly misleading AI benchmark results, with OpenAI employees questioning its claims about Grok 3โ€™s performance.

BT and Equinix expand partnership to enhance global interconnectivity

BT and Equinix expand their partnership to boost interconnectivity for multinational businesses, deploying BTโ€™s Global Fabric NaaS in 40+ Equinix data centres worldwide.

LG unveils new SKS branding for luxury kitchen suite at KBIS 2025

LG rebrands Signature Kitchen Suite to SKS at KBIS 2025, introducing new luxury appliances like a free-zone induction range and an advanced island system.

LG unveils advanced laundry solutions at KBIS 2025

LG unveils its latest heat pump washer and dryer lineup at KBIS 2025, featuring AI-driven efficiency, ventless design, and smart connectivity.

Related Articles