Thanksgiving 2023 security incident
blog.cloudflare.com
Thanksgiving 2023 security incident
1–10 of 336 posts
Re: Thanksgiving 2023 security incident
#2Re: Thanksgiving 2023 security incident
#3Re: Thanksgiving 2023 security incident
#4The most surprising part of this is that Cloudflare uses BitBucket.
Re: Thanksgiving 2023 security incident
#5> The threat actor also attempted to access a console server in our new, and not yet in production, data center in São Paulo. All attempts to gain access were unsuccessful. To ensure these systems are 100% secure, equipment in the Brazil data center was returned to the manufacturers. The manufacturers’ forensic teams examined all of our systems to ensure that no access or persistence was gained. Nothing was found, but we replaced the hardware anyway.
They didn't have to go this far. It would have been really easy not to. But they did and I think that's worthy of kudos.
Re: Thanksgiving 2023 security incident
#6I'm curious if they're rethinking being on Okta.
Re: Thanksgiving 2023 security incident
#7Re: Thanksgiving 2023 security incident
#8> we were (for the second time) the victim of a compromise of Okta’s systems I'm curious if they're rethinking being on Okta.
Re: Thanksgiving 2023 security incident
#9> Over the next day, the threat actor viewed 120 code repositories (out of a total of 11,904 repositories
> They accessed 36 Jira tickets (out of a total of 2,059,357 tickets) and 202 wiki pages (out of a total of 14,099 pages).
Is it just me or 12K git repos and 2 million JIRA tickets sound like a crazy lot. 15K wiki pages is not that high though.
> Since the Smartsheet service account had administrative access to Atlassian Jira, the threat actor was able to install the Sliver Adversary Emulation Framework, which is a widely used tool and framework that red teams and attackers use to enable “C2” (command and control), connectivity gaining persistent and stealthy access to a computer on which it is installed. Sliver was installed using the ScriptRunner for Jira plugin.
> This allowed them continuous access to the Atlassian server, and they used this to attempt lateral movement. With this access the Threat Actor attempted to gain access to a non-production console server in our São Paulo, Brazil data center due to a non-enforced ACL.
Ouch. Full access to a server OS is always scary.
Re: Thanksgiving 2023 security incident
#10Which "nation state" do we think this was?