Live data from Hacker News

US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

zdnet.com

1–10 of 344 posts

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#2
Twitter link to a case of the vulnerability being exploited: https://twitter.com/th3_protoCOL/status/1433414685299142660

NIST Link to issue: https://nvd.nist.gov/vuln/detail/CVE-2021-26084

Tweet from USCYBERCOM urging users to patch: https://twitter.com/CNMF_CyberAlert/status/14337876717851852...

Tweet from BadPackets showing where the bad actors are originating from: https://twitter.com/bad_packets/status/1433157632370511873

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#3
A colleague who runs security at an ASX 200 company found crypto mining running within a day of the vulnerability being announced. They've since patched and cleaned up the hosts they run Data Centre on. Patch quickly, and check for the IoCs listed in Daniaal's tweet below.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#4
I am not in the least bit shocked.

Atlassian products are some of the worst glued-together garbage in the industry. The entire product surface area is probably rife with exploits.

Using Confluence or Jira will show you just how much Atlassian cares about its own products.

I'd love for this to be the straw that breaks the camel's back and makes IT/infosec orgs move away from this bilge.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#6
post #4

I am not in the least bit shocked. Atlassian products are some of the worst glued-together garbage in the industry. The entire product surface area is probably rife with exploits. Using Confluence or Jira will show you just how much Atlassian cares about its own products. I'd love for this to be the straw that breaks the camel's back and makes IT/infosec orgs move away from this bilge.

Any suggestions on what to use instead of Confluence? Need to run on-prem, it's mostly the wiki-like features I'm interested in.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#7
post #5

Why are internally hosted instances even available on the public internet?

So that users can be at home or on a mobile device without requiring them to have VPN.

But so that you still can ensure data-locality or run a customised instance e.t.c. if you have requirements around that. Plus licensing is approx. 40% of the full SaaS cost at scale so may be cheaper to deploy that way.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#9
post #7
post #5

Why are internally hosted instances even available on the public internet?

So that users can be at home or on a mobile device without requiring them to have VPN. But so that you still can ensure data-locality or run a customised instance e.t.c. if you have requirements around that. Plus licensing is approx. 40% of the full SaaS cost at scale so may be cheaper to deploy that way.

But why are they not using VPN?
Post reply on HN