Atlassian confirms ransomware is exploiting latest Confluence bug
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-26084 | Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability CVE-2021-26084 is an OGNL injection vulnerability (CWE-917) in Atlassian Confluence Server and Data Center that may allow an unauthenticated attacker to execute arbitrary code. Any organization running Confluence Server or Data Center is potentially affected. It is significant because it is listed in CISA's Known Exploited Vulnerabilities catalog with known ransomware use, and EPSS assigns a 100.0% probability of exploitation within 30 days (100th percentile). Do: Apply updates to Confluence Server and Data Center per Atlassian's instructions, which is the required action in the CISA KEV listing. Prioritize remediation given confirmed in-the-wild exploitation and known ransomware use. | 9.8 | 100% | KEV ransomware PoC |
| — | |
| CVE-2023-22518 | Improper Authorization in Atlassian Confluence Data Center and Server Atlassian Confluence Data Center and Server contain an improper authorization flaw (CWE-863) that can be triggered by an unauthenticated attacker sending crafted requests to a vulnerable instance. Successful exploitation gives the attacker control over the instance and can cause significant data loss, such as wiping or resetting the Confluence site, but there is no confidentiality impact because no data can be exfiltrated. Any organization running a self-managed Confluence Data Center or Server deployment is in scope. Exploitation is active: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-11-07 with ransomware use noted, and EPSS assigns it a 100% probability of exploitation within 30 days. No public proof-of-concept is known, but ransomware operators are already using the flaw in the wild. Do: Upgrade every Confluence Data Center and Server instance to the patched release for your branch listed in Atlassian's advisory, per the CISA KEV required action (apply vendor mitigations or discontinue use). In the interim, restrict internet access to Confluence and check for signs of compromise such as unexpected instance resets, missing data, or ransom notes; restore from backups if data loss is detected. | 9.8 | 100% | KEV ransomware PoC |
| large≈70,000+ internet-exposed Confluence instances per public scans, likely 100k+ total self-managed installations |
Full article693 words · extracted from therecord.media · click to collapse
Software company Atlassian is now saying that a recently disclosed issue is being exploited by hackers using the Cerber ransomware. An Atlassian spokesperson said Tuesday that the company had evidence to support what cybersecurity researchers reported over the weekend: CVE-2023-22518 — a vulnerability affecting the Confluence Data Center and Confluence Server products — was being used in cybercrime. On Sunday, cybersecurity researchers and incident responders at Rapid7 said that they were seeing exploitation attempts by hackers using Cerber — a ransomware brand thought to be long-defunct. Atlassian had previously made several announcements about the bug but didn’t specify how it was being exploited. “Unpatched instances remain vulnerable and we continue to urge those Confluence Data Center and Server customers to take immediate action,” the Atlassian spokesperson said. The company said it has updated its advisory with information on how customers can detect threats and remediate the issue. Atlassian CISO Bala Sathiamurthy warned the public last week about the bug, which he said could lead to “significant data loss if exploited.” Later in the week, the company updated its advisory to say that while it did not have evidence of an active exploit, it did observe “publicly posted critical information about the vulnerability which increases the risk of exploitation.” “After discovering the unexploited vulnerability, on October 31, 2023, we issued the Critical Security Advisory urging customers to take immediate action. While there was still no known exploit, we issued another wave of communications on November 2, 2023 that noted the increased risk for any customers that had not yet applied the patch after observing publicly posted critical information about the vulnerability,” the Atlassian spokesperson said Tuesday. “On November 3, 2023, we warned customers of an active exploit and escalated this on November 6, 2023 following evidence of malicious activity, including ransomware attacks.” Other companies, like Huntress and Red Canary, backed up Rapid7’s assessment that hackers were using the Cerber ransomware after exploiting the vulnerability. The Cerber ransomware operation was active between 2016 and 2019 but was seen in 2021 targeting Confluence instances vulnerable to another bug, CVE-2021-26084. At the time, the hackers behind the 2021 campaign targeted victims in China, Germany, and the U.S., demanding 0.04 bitcoin in exchange for the decryptor. Several ransomware experts said they had not seen the Cerber ransomware used in years. When asked about the situation, Rapid7 head of vulnerability research Caitlin Condon told Recorded Future News the ransomware note the team extracted was titled “C3RB3R Instructions,” and the files were encrypted with the extension “L0CK3D,” which is a common pattern for Cerber ransomware. “It’s important to note, however, that we’re analyzing and attributing the malware, not the threat actor,” she said. “The ransomware ecosystem has changed and diversified significantly in recent years — source code has been leaked and components reused, adversaries from prominent groups have shifted allegiance (and taken their so-called intellectual property with them), affiliates and access brokers have evolved tactics and techniques, and so on.” Condon went on to note that in other recent attacks, the company has seen hackers use ransomware whose source code was leaked. The theory is that lone-wolf attackers are using the leaked code to “make a quick buck.” The researchers are “analyzing the malware and the artifacts, not attributing the human adversary,” Condon said. Rapid7 said multiple customers are being exploited through CVE-2023-22518 and Red Canary as well as Huntress said they saw the same .LOCK3D file extension in attacks. Huntress researchers said that basic searches of “confluence” on the online Shodan search tool show more than 200,000 possibly vulnerable endpoints and more narrow searches found over 5,600 possibly vulnerable endpoints. But the company noted that neither search proves exploitability or version number and only “demonstrate that Confluence is often publicly accessible.”
Escalating warnings
The return of Cerber
Cerber ransomware note. Image: Rapid7
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/atlassian-confirms-ransomware-using-confluence-bug-cerber