News

Latest news about B2B cyber security >>> PR agencies: add us to your mailing list - see contact! >>> Book an exclusive PartnerChannel for your news!

Attacks on the zero-day vulnerability in Confluence
B2B Cyber ​​Security ShortNews

After the zero-day vulnerability – now known as CVE-2022-26134 – was exposed in Atlassian's collaboration tool Confluence, attackers attempt to exploit it in a targeted manner. The attacks come mainly from Russia, USA, India, Netherlands and Germany. Confluence touts “the remote-ready workspace for your team, where knowledge and collaboration meet.” This work is currently endangered by a security vulnerability. Security analysts from Barracuda have now analyzed data from the cloud security specialist's worldwide installations and have identified an increasing number of attempted attacks via the vulnerability. These range from harmless intentions to some more complex attempts to infect systems with DDoS botnet malware and cryptominers...

Read more

Vulnerabilities in Confluence and Azure
Vulnerabilities in Confluence and Azure

Remote Code Execution (RCE) describes the execution of arbitrary code on a computer system where the attacker does not have direct access to the console. By exploiting security holes, a hacker can remotely take full control of the system. This is the case with security gaps in Confluence and Azure. For example, any user with access to an endpoint with a vulnerable software version can execute any command via an HTTP request without the need for an authorization header. The expected response to this request would be an "Unauthorized" 401 response page. However, the user can command commands with ...

Read more