Thursday, 19 December 2024
28.5 C
Singapore

Microsoft alerts on nation-state hackers exploiting Atlassian Confluence vulnerability

Microsoft identifies a critical Atlassian Confluence vulnerability exploited by nation-state actor Storm-0062, urging companies to update their software to mitigate risks.

Microsoft has identified a severe vulnerability in the Atlassian Confluence Data Center and Server, which, it says, has been exploited by a nation-state entity known as Storm-0062 (also referred to as DarkShadow or Oro0lxy).

According to Microsoft’s threat intelligence crew, the exploit has been observed in action since September 14, 2023.

The vulnerability, labelled as CVE-2023-22515, is described as a critical privilege escalation flaw within Atlassian’s Confluence Data Center and Server. This flaw could be exploited if a device is network-connected to a susceptible application, allowing the perpetrator to create an administrator account within the Confluence application.

The cybersecurity implications

CVE-2023-22515, with a maximum severity score of 10.0 on the CVSS scale, enables remote attackers to fabricate unauthorized administrator accounts and gain access to Confluence servers. Atlassian has released patches for this flaw in its versions 8.3.3, 8.4.3 and 8.5.2 (Long Term Support release) or later.

The exact extent of the attacks remains unclear. Still, Atlassian became aware of the issue through reports from a few customers, indicating that the threat actor exploited this vulnerability as a zero-day.

Notably, Oro0lxy is a digital pseudonym used by Li Xiaoyu, a hacker from China who, as per the U.S. Department of Justice (DoJ) allegations in July 2020, infiltrated numerous companies across the U.S., Hong Kong, and China, Moderna – a coronavirus vaccine research developer, being among them.

Xiaoyu is believed to be associated with the Guangdong regional division of China’s Ministry of State Security (MSS), operated at times for personal gain and at others for the advantage of MSS or other Chinese government entities, as per the DoJ. The DoJ described the hacking activities as a significant and sophisticated threat involving the theft of terabytes of data from U.S. networks.

Companies using Confluence applications are strongly advised to update to the newest versions to lessen the risks and to keep these applications off the public until the remedial measures are implemented.

Hot this week

Huawei unveils Mate X6 foldable phone globally

Huawei’s Mate X6 foldable phone debuts globally with advanced cameras, multitasking displays, and durable design. Learn about its features here.

Qualcomm may be working on a powerful gaming desktop chip

According to a leak, Qualcomm may bring Snapdragon X Elite Gen 2 chips to gaming desktops. Could ARM-powered gaming PCs be the future?

Apple’s next AirTag could track items over longer distances

Apple’s next AirTag is expected to triple its tracking range with a new UWB chip, offering improved Precision Finding for locating items.

Twilio leads in the 2024-2025 IDC MarketScape for B2C customer data platforms

Discover why Twilio Segment leads in the IDC MarketScape for B2C Customer Data Platforms, featuring innovative AI and data management solutions.

WhatsApp introduces new calling features for desktop and mobile users

WhatsApp rolls out group call tools, fun video effects, and improved desktop features to make communication more engaging and seamless.

Salesforce: How ASEAN businesses will lead the AI-driven future in 2025

Salesforce shares its 2025 predictions for ASEAN, highlighting AI-driven innovations like autonomous agents, robotics, and specialised models reshaping business.

Salesforce announces major hiring spree to boost AI sales

Salesforce plans to hire 2,000 sales reps to meet AI demand, marking growth despite recent layoffs, as it focuses on expanding its AI offerings.

Why human skills remain essential in software development’s AI era

Developers’ critical thinking and creativity remain essential as AI tools like GenAI assist in coding. Learn why human skills still matter in the AI era.

NVIDIA’s new compact generative AI supercomputer is its most affordable yet

NVIDIA unveils its Jetson Orin Nano Super Developer Kit, a compact AI supercomputer with enhanced performance and an affordable US$249 price tag.

Related Articles

Popular Categories