Sunday, 19 January 2025
25.9 C
Singapore

Microsoft alerts on nation-state hackers exploiting Atlassian Confluence vulnerability

Microsoft identifies a critical Atlassian Confluence vulnerability exploited by nation-state actor Storm-0062, urging companies to update their software to mitigate risks.

Microsoft has identified a severe vulnerability in the Atlassian Confluence Data Center and Server, which, it says, has been exploited by a nation-state entity known as Storm-0062 (also referred to as DarkShadow or Oro0lxy).

According to Microsoft’s threat intelligence crew, the exploit has been observed in action since September 14, 2023.

The vulnerability, labelled as CVE-2023-22515, is described as a critical privilege escalation flaw within Atlassian’s Confluence Data Center and Server. This flaw could be exploited if a device is network-connected to a susceptible application, allowing the perpetrator to create an administrator account within the Confluence application.

The cybersecurity implications

CVE-2023-22515, with a maximum severity score of 10.0 on the CVSS scale, enables remote attackers to fabricate unauthorized administrator accounts and gain access to Confluence servers. Atlassian has released patches for this flaw in its versions 8.3.3, 8.4.3 and 8.5.2 (Long Term Support release) or later.

The exact extent of the attacks remains unclear. Still, Atlassian became aware of the issue through reports from a few customers, indicating that the threat actor exploited this vulnerability as a zero-day.

Notably, Oro0lxy is a digital pseudonym used by Li Xiaoyu, a hacker from China who, as per the U.S. Department of Justice (DoJ) allegations in July 2020, infiltrated numerous companies across the U.S., Hong Kong, and China, Moderna – a coronavirus vaccine research developer, being among them.

Xiaoyu is believed to be associated with the Guangdong regional division of China’s Ministry of State Security (MSS), operated at times for personal financial gain and at others for the advantage of MSS or other Chinese government entities, as per the DoJ. The DoJ described the hacking activities as a significant and sophisticated threat involving the theft of terabytes of data from U.S. networks.

Companies using Confluence applications are strongly advised to update to the newest versions to lessen the risks and to keep these applications off the public internet until the remedial measures are implemented.

Hot this week

Sterra launches dehumidifiers to improve home comfort and air quality

Sterra introduces the Ray and Titan dehumidifiers, offering advanced humidity control and air purification for healthier, more comfortable homes.

DJI Flip: A US$439 foldable camera drone built for portability

Discover the DJI Flip, a US$439 foldable camera drone with 4K recording, 48MP photos, and 31-minute battery life, perfect for photographers on the go.

Perplexity AI proposes merger with TikTok US

Perplexity AI submitted a merger bid for TikTok US, aiming to integrate video into its AI search engine before the ban deadline.

Proofpoint recognised as a leader in Gartner report for digital communications governance and archiving solutions

Proofpoint named a leader in 2025 Gartner Magic Quadrant for digital communications governance and archiving, excelling in vision and execution.

A city becomes a surprising centre for surveillance tech

Barcelona is becoming a surprising hub for spyware startups, raising ethical concerns over its role in the global surveillance tech industry.

Perplexity AI proposes merger with TikTok US

Perplexity AI submitted a merger bid for TikTok US, aiming to integrate video into its AI search engine before the ban deadline.

FTC raises concerns over big tech partnerships with AI developers

The FTC report warns that big tech partnerships with AI developers could harm competition by limiting resource access and raising costs.

TikTok goes dark in the US as federal ban takes effect

TikTok goes dark in the US after a federal ban takes effect, leaving millions without the app as the government debates its future.

ASUS introduces ProArt Display 5K PA27JCV for creative professionals

ASUS unveils the ProArt Display 5K PA27JCV, a 27-inch monitor offering 5K resolution, Delta E<2 colour accuracy, and advanced features for creators.

Related Articles