CVE-2019-3396
published 2019-03-25CVE-2019-3396: The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed…
PriorityP199critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
99.91%
100.0th percentile
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | confluence_server | < 6.6.12 | 6.6.12 |
| atlassian | confluence_server | >= 6.13.0 < 6.13.3 | 6.13.3 |
| atlassian | confluence_server | >= 6.14.0 < 6.14.2 | 6.14.2 |
| atlassian | confluence_server | >= 6.7.0 < unspecified | unspecified |
| atlassian | confluence_server | >= 6.7.0 < 6.12.3 | 6.12.3 |
| atlassian | confluence_server | >= next of 6.13.0 < unspecified | unspecified |
| atlassian | confluence_server | >= next of 6.14.0 < unspecified | unspecified |
| atlassian | confluence_server | >= unspecified < 6.6.12 | 6.6.12 |
| atlassian | confluence_server | >= unspecified < 6.12.3 | 6.12.3 |
| atlassian | confluence_server | >= unspecified < 6.13.3 | 6.13.3 |
| atlassian | confluence_server | >= unspecified < 6.14.2 | 6.14.2 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2019-3396 is exploited via server-side template injection in the Widget Connector macro of Atlassian Confluence Server; monitor HTTP requests targeting the Widget Connector macro endpoint for template injection payloads (path traversal sequences and SSTI syntax). ↗
- →Exploitation of CVE-2019-3396 has been observed delivering AESDDoS botnet malware capable of DDoS attacks, remote code execution, and cryptocurrency mining — alert on post-exploitation behaviors such as unexpected outbound connections and crypto-mining processes on Confluence hosts. ↗
- ·Affected versions span multiple release families; ensure detection/patching coverage includes all branches: 6.6.0–6.6.11, 6.7.0–6.12.2, 6.13.0–6.13.2, and 6.14.0–6.14.1. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability
cisa·2021-11-03·CVSS 9.8
CVE-2019-3396 [CRITICAL] CWE-22 Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability
Vulnerability: Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability
Affected: Atlassian Confluence Server and Data Server
Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-3396
Remediation Due Date: 2022-05-03
GHSA
OpenNMS Horizon RCE via JEXL2 expression
ghsa·2022-05-24
CVE-2021-3396 [HIGH] CWE-863 OpenNMS Horizon RCE via JEXL2 expression
OpenNMS Horizon RCE via JEXL2 expression
OpenNMS Meridian 2016, 2017, 2018 before 2018.1.25, 2019 before 2019.1.16, and 2020 before 2020.1.5, Horizon 1.2 through 27.0.4, and Newts <1.5.3 has Incorrect Access Control, which allows local and remote code execution using JEXL expressions.
GHSA
GHSA-fr34-8fhg-2m6q: The Widget Connector macro in Atlassian Confluence Server before version 6
ghsa_unreviewed·2022-05-13
CVE-2019-3396 [CRITICAL] CWE-22 GHSA-fr34-8fhg-2m6q: The Widget Connector macro in Atlassian Confluence Server before version 6
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.
VulnCheck
Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability
vulncheck·2019·CVSS 9.8
CVE-2019-3396 [CRITICAL] CWE-22 Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability
Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability
Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.
Affected: Atlassian Confluence Server and Data Center
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.alertlogic.com/blog/active-exploitation-of-confluence-vulnerability-cve-2019-3396-dropping-gandcrab-ransomware/; https://www.bleepingcomputer.com/news/security/vulnerable-confluence-servers-get-infected-with-ransomware-trojans/; https://www.tenable.com/blog/cve-2019-3396-vulnerability-in-atlassian-confluence-widget-connector-exploited-in-the
Suricata
ET WEB_CLIENT Possible Confluence SSTI Exploitation Attempt - Leads to RCE/LFI (CVE-2019-3396)
suricata·2019-05-08·CVSS 9.8
CVE-2019-3396 [CRITICAL] ET WEB_CLIENT Possible Confluence SSTI Exploitation Attempt - Leads to RCE/LFI (CVE-2019-3396)
ET WEB_CLIENT Possible Confluence SSTI Exploitation Attempt - Leads to RCE/LFI (CVE-2019-3396)
Rule: alert http any any -> $HTTP_SERVERS any (msg:"ET WEB_CLIENT Possible Confluence SSTI Exploitation Attempt - Leads to RCE/LFI (CVE-2019-3396)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/rest/tinymce/1/macro/preview"; fast_pattern; endswith; http.request_body; content:"|22|contentId|22|"; depth:20; content:"|22|_template|22 3a|"; distance:0; reference:url,packetstormsecurity.com/files/152568/Atlassian-Confluence-Widget-Connector-Macro-Velocity-Template-Injection.html; classtype:attempted-admin; sid:2027333; rev:4; metadata:created_at 2019_05_08, cve CVE_2019_3396, deployment Perimeter, deployment Internal, performance_impact Low, confidence Medium, signatur
Exploit-DB
Atlassian Confluence Widget Connector Macro - SSTI
exploitdb·2021-01-22·CVSS 9.8
CVE-2019-3396 [CRITICAL] Atlassian Confluence Widget Connector Macro - SSTI
Atlassian Confluence Widget Connector Macro - SSTI
---
# Exploit Title: Atlassian Confluence Widget Connector Macro - SSTI
# Date: 21-Jan-2021
# Exploit Author: 46o60
# Vendor Homepage: https://www.atlassian.com/software/confluence
# Software Link: https://product-downloads.atlassian.com/software/confluence/downloads/atlassian-confluence-6.12.1-x64.bin
# Version: 6.12.1
# Tested on: Ubuntu 20.04.1 LTS
# CVE : CVE-2019-3396
#!/usr/bin/env python3
# -*- coding: UTF-8 -*-
"""
Exploit for CVE-2019-3396 (https://www.cvedetails.com/cve/CVE-2019-3396/) Widget Connector macro in Atlassian
Confluence Server server-side template injection.
Vulnerability information:
Authors:
Daniil Dmitriev - Discovering vulnerability
Dmitry (rrock) Shchannikov - Metasploit module
Exploit
ExploitDB:
https://www
Exploit-DB
Atlassian Confluence Widget Connector Macro - Velocity Template Injection (Metasploit)
exploitdb·2019-04-19·CVSS 9.8
CVE-2019-3396 [CRITICAL] Atlassian Confluence Widget Connector Macro - Velocity Template Injection (Metasploit)
Atlassian Confluence Widget Connector Macro - Velocity Template Injection (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule "Atlassian Confluence Widget Connector Macro Velocity Template Injection",
'Description' => %q{
Widget Connector Macro is part of Atlassian Confluence Server and Data Center that
allows embed online videos, slideshows, photostreams and more directly into page.
A _template parameter can be used to inject remote Java code into a Velocity template,
and gain code execution. Authentication is unrequired to exploit this vulnerability.
By default, Java payload will be used because it is cross-platform, but you can also
specify which native payloa
Metasploit
Atlassian Confluence Widget Connector Macro Velocity Template Injection
metasploit
Atlassian Confluence Widget Connector Macro Velocity Template Injection
Atlassian Confluence Widget Connector Macro Velocity Template Injection
Widget Connector Macro is part of Atlassian Confluence Server and Data Center that allows embed online videos, slideshows, photostreams and more directly into page. A _template parameter can be used to inject remote Java code into a Velocity template, and gain code execution. Authentication is unrequired to exploit this vulnerability. By default, Java payload will be used because it is cross-platform, but you can also specify which native payload you want (Linux or Windows). Confluence before version 6.6.12, from version 6.7.0 before 6.12.3, from version 6.13.0 before 6.13.3 and from version 6.14.0 before 6.14.2 are affected. This vulnerability was originally discovered by Daniil Dmitriev https://twitter.com/ddv_ua.
Nuclei
Atlassian Confluence Server - Path Traversal
nuclei·CVSS 9.8
CVE-2019-3396 [CRITICAL] Atlassian Confluence Server - Path Traversal
Atlassian Confluence Server - Path Traversal
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.
Template:
id: CVE-2019-3396
info:
name: Atlassian Confluence Server - Path Traversal
author: harshbothra_
severity: critical
description: The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.
Tenable
CVE-2021-26084: Atlassian Confluence OGNL Injection Vulnerability Exploited in the Wild
blogs_tenable·2021-09-07·CVSS 9.8
[CRITICAL] CVE-2021-26084: Atlassian Confluence OGNL Injection Vulnerability Exploited in the Wild
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
Manage Zero Day Exploits (ZDI) with Trend Micro Solutions
blogs_trendmicro·2021-04-28
Manage Zero Day Exploits (ZDI) with Trend Micro Solutions
Cyberbedrohungen
## How Trend Micro Helps Manage Exploited Vulnerabilities
As technological innovations evolve, protecting companies from cyber threats tomorrow secures their businesses today. Read how Trend Micro protects customers from vulnerability exploits by blocking them as early as possible.
By: Jon Clay Apr 28, 2021 Read time: ( words)
Save to Folio
As technological innovations evolve, protecting companies from cyber threats tomorrow secures their businesses today. Exploiting known vulnerabilities to successfully compromise an organization has long been a common tactic used by malicious actors. Whether Heartbleed, EternalBlue, or most recently Zerologon, threat actors take advantage of newly disclosed vulnerabilities in their attacks. But even with thousands of new vulnerabili
Trendmicro
Manage Zero Day Exploits (ZDI) with Trend Micro Solutions
blogs_trendmicro·2021-04-28
Manage Zero Day Exploits (ZDI) with Trend Micro Solutions
Cyber Threats
## How Trend Micro Helps Manage Exploited Vulnerabilities
As technological innovations evolve, protecting companies from cyber threats tomorrow secures their businesses today. Read how Trend Micro protects customers from vulnerability exploits by blocking them as early as possible.
By: Jon Clay 2021/04/28 Read time: ( words)
Save to Folio
As technological innovations evolve, protecting companies from cyber threats tomorrow secures their businesses today. Exploiting known vulnerabilities to successfully compromise an organization has long been a common tactic used by malicious actors. Whether Heartbleed, EternalBlue, or most recently Zerologon, threat actors take advantage of newly disclosed vulnerabilities in their attacks. But even with thousands of new vulnerabilities
Trendmicro
Manage Zero Day Exploits (ZDI) with Trend Micro Solutions
blogs_trendmicro·2021-04-28
Manage Zero Day Exploits (ZDI) with Trend Micro Solutions
Minacce cyber
## How Trend Micro Helps Manage Exploited Vulnerabilities
As technological innovations evolve, protecting companies from cyber threats tomorrow secures their businesses today. Read how Trend Micro protects customers from vulnerability exploits by blocking them as early as possible.
By: Jon Clay Apr 28, 2021 Read time: ( words)
Save to Folio
As technological innovations evolve, protecting companies from cyber threats tomorrow secures their businesses today. Exploiting known vulnerabilities to successfully compromise an organization has long been a common tactic used by malicious actors. Whether Heartbleed, EternalBlue, or most recently Zerologon, threat actors take advantage of newly disclosed vulnerabilities in their attacks. But even with thousands of new vulnerabilitie
Trendmicro
Manage Zero Day Exploits (ZDI) with Trend Micro Solutions
blogs_trendmicro·2021-04-28
Manage Zero Day Exploits (ZDI) with Trend Micro Solutions
Ciberamenazas
## How Trend Micro Helps Manage Exploited Vulnerabilities
As technological innovations evolve, protecting companies from cyber threats tomorrow secures their businesses today. Read how Trend Micro protects customers from vulnerability exploits by blocking them as early as possible.
By: Jon Clay Apr 28, 2021 Read time: ( words)
Save to Folio
As technological innovations evolve, protecting companies from cyber threats tomorrow secures their businesses today. Exploiting known vulnerabilities to successfully compromise an organization has long been a common tactic used by malicious actors. Whether Heartbleed, EternalBlue, or most recently Zerologon, threat actors take advantage of newly disclosed vulnerabilities in their attacks. But even with thousands of new vulnerabilitie
Trendmicro
Manage Zero Day Exploits (ZDI) with Trend Micro Solutions
blogs_trendmicro·2021-04-28
Manage Zero Day Exploits (ZDI) with Trend Micro Solutions
Cyber Threats
## How Trend Micro Helps Manage Exploited Vulnerabilities
As technological innovations evolve, protecting companies from cyber threats tomorrow secures their businesses today. Read how Trend Micro protects customers from vulnerability exploits by blocking them as early as possible.
By: Jon Clay Apr 28, 2021 Read time: ( words)
Save to Folio
As technological innovations evolve, protecting companies from cyber threats tomorrow secures their businesses today. Exploiting known vulnerabilities to successfully compromise an organization has long been a common tactic used by malicious actors. Whether Heartbleed, EternalBlue, or most recently Zerologon, threat actors take advantage of newly disclosed vulnerabilities in their attacks. But even with thousands of new vulnerabilitie
Trendmicro
Manage Zero Day Exploits (ZDI) with Trend Micro Solutions
blogs_trendmicro·2021-04-28
Manage Zero Day Exploits (ZDI) with Trend Micro Solutions
Cyber Threats
# How Trend Micro Helps Manage Exploited Vulnerabilities
As technological innovations evolve, protecting companies from cyber threats tomorrow secures their businesses today. Read how Trend Micro protects customers from vulnerability exploits by blocking them as early as possible.
By: Jon Clay
2021/04/28
Read time: ( words)
Save to Folio
Photo credit: pxhere
As technological innovations evolve, protecting companies from cyber threats tomorrow secures their businesses today. Exploiting known vulnerabilities to successfully compromise an organization has long been a common tactic used by malicious actors. Whether Heartbleed, EternalBlue, or most recently Zerologon, threat actors take advantage of newly disclosed vulnerabilities in their attacks. But even with thousands o
Tenable
Government Agencies Warn of State-Sponsored Actors Exploiting Publicly Known Vulnerabilities
blogs_tenable·2020-10-23
Government Agencies Warn of State-Sponsored Actors Exploiting Publicly Known Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
NSA Alert: Chinese State-Sponsored Actors Exploit Known Vulnerabilities | Qualys
blogs_qualys·2020-10-22·CVSS 9.8
CVE-2020-15505 [CRITICAL] NSA Alert: Chinese State-Sponsored Actors Exploit Known Vulnerabilities | Qualys
#### Table of Contents
- Detect 25 Publicly Known Vulnerabilities using VMDR
Update November 25, 2020: The UK National Cyber Security Centre alerts that APT nation-state groups and cybercriminals are exploiting MobileIron RCE vulnerability (CVE-2020-15505).
Original post: On October 20, 2020, the United States National Security Agency (NSA) released a cybersecurity advisory on Chinese state-sponsored malicious cyber activity. The NSA alert provided a list of 25 publicly known vulnerabilities that are known to be recently leveraged by cyber actors for various hacking operations.
“Since these techniques include exploitation of publicly known vulnerabilities, it is critical that network defenders prioritize patching and
mitigation efforts,” said the NSA advisory. It also recommended “crit
Qualys
NSA Alert: Chinese State-Sponsored Actors Exploit Known Vulnerabilities
blogs_qualys·2020-10-22·CVSS 10.0
CVE-2020-15505 [CRITICAL] NSA Alert: Chinese State-Sponsored Actors Exploit Known Vulnerabilities
## Table of Contents
Detect 25 Publicly Known Vulnerabilities using VMDR
Update November 25, 2020 : The UK National Cyber Security Centre alerts that APT nation-state groups and cybercriminals are exploiting MobileIron RCE vulnerability (CVE-2020-15505).
Original post : On October 20, 2020, the United States National Security Agency (NSA) released a cybersecurity advisory on Chinese state-sponsored malicious cyber activity. The NSA alert provided a list of 25 publicly known vulnerabilities that are known to be recently leveraged by cyber actors for various hacking operations.
“Since these techniques include exploitation of publicly known vulnerabilities, it is critical that network defenders prioritize patching and mitigation efforts,” said the NSA advisory. It also recommended “critic
Trendmicro
Exposed Docker Server Abused to Drop Cryptominer DDoS Bot
blogs_trendmicro·2020-09-08
Exposed Docker Server Abused to Drop Cryptominer DDoS Bot
Cloud
## Exposed Docker Server Abused to Drop Cryptominer, DDoS Bot
Malicious actors continue to target environments running Docker containers. We recently encountered an attack that drops both a malicious cryptocurrency miner and a DDoS bot on a Docker container built using Alpine Linux as its base image.
By: Augusto Remillano II Sep 08, 2020 Read time: ( words)
Save to Folio
Malicious actors continue to target environments running Docker containers . We recently encountered an attack that drops both a malicious cryptocurrency miner and a distributed denial-of-service (DDoS) bot on a Docker container built using Alpine Linux as its base image. A similar attack was also reported by Trend Micro in May; in that previous attack, threat actors created a malicious Alpine Linux container to
Trendmicro
Exposed Docker Server Abused to Drop Cryptominer DDoS Bot
blogs_trendmicro·2020-09-08
Exposed Docker Server Abused to Drop Cryptominer DDoS Bot
Nube
## Exposed Docker Server Abused to Drop Cryptominer, DDoS Bot
Malicious actors continue to target environments running Docker containers. We recently encountered an attack that drops both a malicious cryptocurrency miner and a DDoS bot on a Docker container built using Alpine Linux as its base image.
By: Augusto Remillano II Sep 08, 2020 Read time: ( words)
Save to Folio
Malicious actors continue to target environments running Docker containers . We recently encountered an attack that drops both a malicious cryptocurrency miner and a distributed denial-of-service (DDoS) bot on a Docker container built using Alpine Linux as its base image. A similar attack was also reported by Trend Micro in May; in that previous attack, threat actors created a malicious Alpine Linux container to
Trendmicro
Exposed Docker Server Abused to Drop Cryptominer DDoS Bot
blogs_trendmicro·2020-09-08
Exposed Docker Server Abused to Drop Cryptominer DDoS Bot
Cloud
## Exposed Docker Server Abused to Drop Cryptominer, DDoS Bot
Malicious actors continue to target environments running Docker containers. We recently encountered an attack that drops both a malicious cryptocurrency miner and a DDoS bot on a Docker container built using Alpine Linux as its base image.
By: Augusto Remillano II 2020/09/08 Read time: ( words)
Save to Folio
Malicious actors continue to target environments running Docker containers . We recently encountered an attack that drops both a malicious cryptocurrency miner and a distributed denial-of-service (DDoS) bot on a Docker container built using Alpine Linux as its base image. A similar attack was also reported by Trend Micro in May; in that previous attack, threat actors created a malicious Alpine Linux container to a
Trendmicro
Exposed Docker Server Abused to Drop Cryptominer DDoS Bot
blogs_trendmicro·2020-09-08
Exposed Docker Server Abused to Drop Cryptominer DDoS Bot
Cloud
# Exposed Docker Server Abused to Drop Cryptominer, DDoS Bot
Malicious actors continue to target environments running Docker containers. We recently encountered an attack that drops both a malicious cryptocurrency miner and a DDoS bot on a Docker container built using Alpine Linux as its base image.
By: Augusto Remillano II
2020/09/08
Read time: ( words)
Save to Folio
Malicious actors continue to target environments running Docker containers. We recently encountered an attack that drops both a malicious cryptocurrency miner and a distributed denial-of-service (DDoS) bot on a Docker container built using Alpine Linux as its base image. A similar attack was also reported by Trend Micro in May; in that previous attack, threat actors created a malicious Alpine Linux container to al
Securelist
MATA: Multi-platform targeted malware framework
blogs_securelist·2020-07-22
MATA: Multi-platform targeted malware framework
Authors
- GReAT
As the IT and OT environment becomes more complex, adversaries are quick to adapt their attack strategy. For example, as users’ work environments diversify, adversaries are busy acquiring the TTPs to infiltrate systems. Recently, we reported to our Threat Intelligence Portal customers a similar malware framework that internally we called MATA. The MATA malware framework possesses several components, such as loader, orchestrator and plugins. This comprehensive framework is able to target Windows, Linux and macOS operating systems.
The first artefacts we found relating to MATA were used around April 2018. After that, the actor behind this advanced malware framework used it aggressively to infiltrate corporate entities around the world. We identified several victims from ou
Securelist
MATA: Multi-platform targeted malware framework
blogs_securelist·2020-07-22
MATA: Multi-platform targeted malware framework
Authors
GReAT
As the IT and OT environment becomes more complex, adversaries are quick to adapt their attack strategy. For example, as users’ work environments diversify, adversaries are busy acquiring the TTPs to infiltrate systems. Recently, we reported to our Threat Intelligence Portal customers a similar malware framework that internally we called MATA. The MATA malware framework possesses several components, such as loader, orchestrator and plugins. This comprehensive framework is able to target Windows, Linux and macOS operating systems.
The first artefacts we found relating to MATA were used around April 2018. After that, the actor behind this advanced malware framework used it aggressively to infiltrate corporate entities around the world. We identified several victims from our
Qualys
Top 19+ Vulnerability CVEs in Santa’s Dashboard Tracking
blogs_qualys·2019-12-27·CVSS 8.8
[HIGH] Top 19+ Vulnerability CVEs in Santa’s Dashboard Tracking
A recent report identified 19+ vulnerabilities that should be mitigated by end of year 2019. These are a range of top vulnerabilities attacked and leveraged by Advance Persistent Threat (APT) actors from all parts of the world.
The list below shows those top 19 vulnerabilities, and it should be no surprise that you can easily track and remediate them via a dashboard within Qualys. Import the dashboard into your subscription for easy insight into what assets and vulnerabilities in your organization are at risk.
No.
CVE
Products Affected by CVE
CVSS Score (NVD)
Examples of Threat Actors
1
CVE-2017-11882
Microsoft Office
7.8
APT32 (Vietnam), APT34 (Iran), APT40 (China), APT-C-35 (India), Cobalt Group (Spain, Ukraine), Silent Group (Russia), Lotus Blossom (China), FIN7 (Russia)
2
Qualys
Top 19+ Vulnerability CVEs in Santa’s Dashboard Tracking | Qualys
blogs_qualys·2019-12-27·CVSS 8.8
[HIGH] Top 19+ Vulnerability CVEs in Santa’s Dashboard Tracking | Qualys
A recent report identified 19+ vulnerabilities that should be mitigated by end of year 2019. These are a range of top vulnerabilities attacked and leveraged by Advance Persistent Threat (APT) actors from all parts of the world.
The list below shows those top 19 vulnerabilities, and it should be no surprise that you can easily track and remediate them via a dashboard within Qualys. Import the dashboard into your subscription for easy insight into what assets and vulnerabilities in your organization are at risk.
No.
CVE
Products Affected by CVE
CVSS Score (NVD)
Examples of Threat Actors
1
CVE-2017-11882
Microsoft Office
7.8
APT32 (Vietnam), APT34 (Iran), APT40 (China), APT-C-35 (India), Cobalt Group (Spain, Ukraine), Silent Group (Russia), Lotus Blossom (China), FIN7 (Russia)
2
CVE-2018-
Tenable
Objects in Mirror Are Closer Than They Appear: Reflecting on the Cybersecurity Threats from 2019
blogs_tenable·2019-12-16
Objects in Mirror Are Closer Than They Appear: Reflecting on the Cybersecurity Threats from 2019
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
CVE-2019-11581: Critical Template Injection Vulnerability in Atlassian Jira Server and Data Center
blogs_tenable·2019-07-11·CVSS 9.8
[CRITICAL] CVE-2019-11581: Critical Template Injection Vulnerability in Atlassian Jira Server and Data Center
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
8th July – Threat Intelligence Bulletin
blogs_checkpoint·2019-07-08·CVSS 7.8
CVE-2018-7600 [HIGH] 8th July – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 8th July – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 8th July 2019, please download our Threat Intelligence Bulletin
TOP ATTACKS AND BREACHES
The Japanese-American international convenience store 7/11 has shut down its new mobile payment app after threat actors stole $500,000 from its users. The attackers were able to perform unwanted charges on customers’ accounts due to a flaw in the password reset function, which allows anyone to reset the password for other cu
Trendmicro
Spreader verbreitet Kryptowährungs-Miner
blogs_trendmicro·2019-07-01
Spreader verbreitet Kryptowährungs-Miner
Malware
## Spreader verbreitet Kryptowährungs-Miner
Ein Golang-basierter Spreader kommt in einer Kampagne zum Einsatz, die einen Kryptowährungs-Miner verteilt. Golang oder Go ist eine quelloffene Programmiersprache, die in letzter Zeit häufig für Malware-Aktivitäten eingesetzt wird.
By: Augusto Remillano II, Mark Vicente Jul 01, 2019 Read time: ( words)
Save to Folio
Originalbeitrag von Augusto Remillano II und Mark Vicente
Ein Golang-basierter Spreader kommt in einer Kampagne zum Einsatz, die einen Kryptowährungs-Miner verteilt. Golang oder Go ist eine quelloffene Programmiersprache, die in letzter Zeit häufig für Malware-Aktivitäten eingesetzt wird. Trend Micro hat bereits im Mai die Nutzung des Spreaders entdeckt und ihn in einer neuen Kampagne wieder gefunden.
Der Spreader scann
Tenable
Stop the Presses: Media Coverage as a Prioritization Metric for Vulnerability Management
blogs_tenable·2019-05-22
Stop the Presses: Media Coverage as a Prioritization Metric for Vulnerability Management
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
CVE-2019-3396: Exploiting the Confluence Vulnerability
blogs_trendmicro·2019-05-07·CVSS 9.8
CVE-2019-3396 [CRITICAL] CVE-2019-3396: Exploiting the Confluence Vulnerability
Cloud
## CVE-2019-3396: Exploiting the Confluence Vulnerability
We discovered the Confluence vulnerability CVE-2019-3396 being used to deliver a cryptocurrency-mining malware containing a rootkit that was designed to hide its activities.
By: Augusto Remillano II, Robert Malagad 2019/05/07 Read time: ( words)
Save to Folio
In March 2019, Atlassian published an advisory covering two critical vulnerabilities involving Confluence, a widely used collaboration and planning software. In April, we observed one of these vulnerabilities, the widget connector vulnerability CVE-2019-3396 , being exploited by threat actors to perform malicious attacks. Security provider Alert Logic also discovered the vulnerability being exploited to drop the Gandcrab ransomware .
It seems that these incidents ar
Trendmicro
CVE-2019-3396: Exploiting the Confluence Vulnerability
blogs_trendmicro·2019-05-07·CVSS 9.8
CVE-2019-3396 [CRITICAL] CVE-2019-3396: Exploiting the Confluence Vulnerability
Cloud
## CVE-2019-3396: Exploiting the Confluence Vulnerability
We discovered the Confluence vulnerability CVE-2019-3396 being used to deliver a cryptocurrency-mining malware containing a rootkit that was designed to hide its activities.
By: Augusto Remillano II, Robert Malagad May 07, 2019 Read time: ( words)
Save to Folio
In March 2019, Atlassian published an advisory covering two critical vulnerabilities involving Confluence, a widely used collaboration and planning software. In April, we observed one of these vulnerabilities, the widget connector vulnerability CVE-2019-3396 , being exploited by threat actors to perform malicious attacks. Security provider Alert Logic also discovered the vulnerability being exploited to drop the Gandcrab ransomware .
It seems that these incidents
Trendmicro
CVE-2019-3396: Exploiting the Confluence Vulnerability
blogs_trendmicro·2019-05-07·CVSS 9.8
CVE-2019-3396 [CRITICAL] CVE-2019-3396: Exploiting the Confluence Vulnerability
Cloud
# CVE-2019-3396: Exploiting the Confluence Vulnerability
We discovered the Confluence vulnerability CVE-2019-3396 being used to deliver a cryptocurrency-mining malware containing a rootkit that was designed to hide its activities.
By: Augusto Remillano II, Robert Malagad
2019/05/07
Read time: ( words)
Save to Folio
In March 2019, Atlassian published an advisory covering two critical vulnerabilities involving Confluence, a widely used collaboration and planning software. In April, we observed one of these vulnerabilities, the widget connector vulnerability CVE-2019-3396, being exploited by threat actors to perform malicious attacks. Security provider Alert Logic also discovered the vulnerability being exploited to drop the Gandcrab ransomware.
It seems that these incidents are
Trendmicro
CVE-2019-3396: Exploiting the Confluence Vulnerability
blogs_trendmicro·2019-05-07·CVSS 9.8
CVE-2019-3396 [CRITICAL] CVE-2019-3396: Exploiting the Confluence Vulnerability
Cloud
# CVE-2019-3396: Exploiting the Confluence Vulnerability
We discovered the Confluence vulnerability CVE-2019-3396 being used to deliver a cryptocurrency-mining malware containing a rootkit that was designed to hide its activities.
By: Augusto Remillano II, Robert Malagad
May 07, 2019
Read time: ( words)
Save to Folio
In March 2019, Atlassian published an advisory covering two critical vulnerabilities involving Confluence, a widely used collaboration and planning software. In April, we observed one of these vulnerabilities, the widget connector vulnerability CVE-2019-3396, being exploited by threat actors to perform malicious attacks. Security provider Alert Logic also discovered the vulnerability being exploited to drop the Gandcrab ransomware.
It seems that these incidents ar
Trendmicro
CVE-2019-3396: Exploiting the Confluence Vulnerability
blogs_trendmicro·2019-05-07·CVSS 9.8
CVE-2019-3396 [CRITICAL] CVE-2019-3396: Exploiting the Confluence Vulnerability
Nube
## CVE-2019-3396: Exploiting the Confluence Vulnerability
We discovered the Confluence vulnerability CVE-2019-3396 being used to deliver a cryptocurrency-mining malware containing a rootkit that was designed to hide its activities.
By: Augusto Remillano II, Robert Malagad May 07, 2019 Read time: ( words)
Save to Folio
In March 2019, Atlassian published an advisory covering two critical vulnerabilities involving Confluence, a widely used collaboration and planning software. In April, we observed one of these vulnerabilities, the widget connector vulnerability CVE-2019-3396 , being exploited by threat actors to perform malicious attacks. Security provider Alert Logic also discovered the vulnerability being exploited to drop the Gandcrab ransomware .
It seems that these incidents a
Tenable
CVE-2019-3396: Vulnerability in Atlassian Confluence Widget Connector Exploited in the Wild
blogs_tenable·2019-04-30·CVSS 9.8
[CRITICAL] CVE-2019-3396: Vulnerability in Atlassian Confluence Widget Connector Exploited in the Wild
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
AESDDoS Botnet Exploits CVE-2019-3396 to Perform RCE
blogs_trendmicro·2019-04-26·CVSS 9.8
CVE-2019-3396 [CRITICAL] AESDDoS Botnet Exploits CVE-2019-3396 to Perform RCE
Exploits & Vulnerabilities
## AESDDoS Botnet Exploits CVE-2019-3396 to Perform RCE
Our honeypot sensors recently detected an AESDDoS botnet malware variant exploiting a server-side template injection vulnerability (CVE-2019-3396) in the Widget Connector macro in Atlassian Confluence Server.
By: Augusto Remillano II, Jakub Urbanec Apr 26, 2019 Read time: ( words)
Save to Folio
Our honeypot sensors recently detected an AESDDoS botnet malware variant (detected by Trend Micro as Backdoor.Linux.AESDDOS.J ) exploiting a server-side template injection vulnerability ( CVE-2019-3396 ) in the Widget Connector macro in Atlassian Confluence Server, a collaboration software program used by DevOps professionals.
We discovered that this malware variant can perform DDoS attacks, remote code executio
Trendmicro
AESDDoS Botnet Exploits CVE-2019-3396 to Perform RCE
blogs_trendmicro·2019-04-26·CVSS 9.8
CVE-2019-3396 [CRITICAL] AESDDoS Botnet Exploits CVE-2019-3396 to Perform RCE
Exploits y vulnerabilidades
## AESDDoS Botnet Exploits CVE-2019-3396 to Perform RCE
Our honeypot sensors recently detected an AESDDoS botnet malware variant exploiting a server-side template injection vulnerability (CVE-2019-3396) in the Widget Connector macro in Atlassian Confluence Server.
By: Augusto Remillano II, Jakub Urbanec Apr 26, 2019 Read time: ( words)
Save to Folio
Our honeypot sensors recently detected an AESDDoS botnet malware variant (detected by Trend Micro as Backdoor.Linux.AESDDOS.J ) exploiting a server-side template injection vulnerability ( CVE-2019-3396 ) in the Widget Connector macro in Atlassian Confluence Server, a collaboration software program used by DevOps professionals.
We discovered that this malware variant can perform DDoS attacks, remote code executi
Trendmicro
AESDDoS Botnet Exploits CVE-2019-3396 to Perform RCE
blogs_trendmicro·2019-04-26·CVSS 9.8
CVE-2019-3396 [CRITICAL] AESDDoS Botnet Exploits CVE-2019-3396 to Perform RCE
Ausnutzung von Schwachstellen
## AESDDoS Botnet Exploits CVE-2019-3396 to Perform RCE
Our honeypot sensors recently detected an AESDDoS botnet malware variant exploiting a server-side template injection vulnerability (CVE-2019-3396) in the Widget Connector macro in Atlassian Confluence Server.
By: Augusto Remillano II, Jakub Urbanec Apr 26, 2019 Read time: ( words)
Save to Folio
Our honeypot sensors recently detected an AESDDoS botnet malware variant (detected by Trend Micro as Backdoor.Linux.AESDDOS.J ) exploiting a server-side template injection vulnerability ( CVE-2019-3396 ) in the Widget Connector macro in Atlassian Confluence Server, a collaboration software program used by DevOps professionals.
We discovered that this malware variant can perform DDoS attacks, remote code execu
Trendmicro
AESDDoS Botnet Exploits CVE-2019-3396 to Perform RCE
blogs_trendmicro·2019-04-26·CVSS 9.8
CVE-2019-3396 [CRITICAL] AESDDoS Botnet Exploits CVE-2019-3396 to Perform RCE
Exploits & Vulnerabilities
# AESDDoS Botnet Exploits CVE-2019-3396 to Perform RCE
Our honeypot sensors recently detected an AESDDoS botnet malware variant exploiting a server-side template injection vulnerability (CVE-2019-3396) in the Widget Connector macro in Atlassian Confluence Server.
By: Augusto Remillano II, Jakub Urbanec
Apr 26, 2019
Read time: ( words)
Save to Folio
Our honeypot sensors recently detected an AESDDoS botnet malware variant (detected by Trend Micro as Backdoor.Linux.AESDDOS.J) exploiting a server-side template injection vulnerability (CVE-2019-3396) in the Widget Connector macro in Atlassian Confluence Server, a collaboration software program used by DevOps professionals.
We discovered that this malware variant can perform DDoS attacks, remote code execution,
Trendmicro
AESDDoS Botnet Exploits CVE-2019-3396 to Perform RCE
blogs_trendmicro·2019-04-26·CVSS 9.8
CVE-2019-3396 [CRITICAL] AESDDoS Botnet Exploits CVE-2019-3396 to Perform RCE
Sfruttamento vulnerabilità
## AESDDoS Botnet Exploits CVE-2019-3396 to Perform RCE
Our honeypot sensors recently detected an AESDDoS botnet malware variant exploiting a server-side template injection vulnerability (CVE-2019-3396) in the Widget Connector macro in Atlassian Confluence Server.
By: Augusto Remillano II, Jakub Urbanec Apr 26, 2019 Read time: ( words)
Save to Folio
Our honeypot sensors recently detected an AESDDoS botnet malware variant (detected by Trend Micro as Backdoor.Linux.AESDDOS.J ) exploiting a server-side template injection vulnerability ( CVE-2019-3396 ) in the Widget Connector macro in Atlassian Confluence Server, a collaboration software program used by DevOps professionals.
We discovered that this malware variant can perform DDoS attacks, remote code executio
Trendmicro
AESDDoS Botnet Exploits CVE-2019-3396 to Perform RCE
blogs_trendmicro·2019-04-26·CVSS 9.8
CVE-2019-3396 [CRITICAL] AESDDoS Botnet Exploits CVE-2019-3396 to Perform RCE
Exploits & Vulnerabilities
# AESDDoS Botnet Exploits CVE-2019-3396 to Perform RCE
Our honeypot sensors recently detected an AESDDoS botnet malware variant exploiting a server-side template injection vulnerability (CVE-2019-3396) in the Widget Connector macro in Atlassian Confluence Server.
By: Augusto Remillano II, Jakub Urbanec
2019/04/26
Read time: ( words)
Save to Folio
Our honeypot sensors recently detected an AESDDoS botnet malware variant (detected by Trend Micro as Backdoor.Linux.AESDDOS.J) exploiting a server-side template injection vulnerability (CVE-2019-3396) in the Widget Connector macro in Atlassian Confluence Server, a collaboration software program used by DevOps professionals.
We discovered that this malware variant can perform DDoS attacks, remote code execution, an
Trendmicro
AESDDoS Botnet Exploits CVE-2019-3396 to Perform RCE
blogs_trendmicro·2019-04-26·CVSS 9.8
CVE-2019-3396 [CRITICAL] AESDDoS Botnet Exploits CVE-2019-3396 to Perform RCE
Exploits & Vulnerabilities
## AESDDoS Botnet Exploits CVE-2019-3396 to Perform RCE
Our honeypot sensors recently detected an AESDDoS botnet malware variant exploiting a server-side template injection vulnerability (CVE-2019-3396) in the Widget Connector macro in Atlassian Confluence Server.
By: Augusto Remillano II, Jakub Urbanec 2019/04/26 Read time: ( words)
Save to Folio
Our honeypot sensors recently detected an AESDDoS botnet malware variant (detected by Trend Micro as Backdoor.Linux.AESDDOS.J ) exploiting a server-side template injection vulnerability ( CVE-2019-3396 ) in the Widget Connector macro in Atlassian Confluence Server, a collaboration software program used by DevOps professionals.
We discovered that this malware variant can perform DDoS attacks, remote code execution,
Threat Intel
APT41 (APT41, Wicked Panda, Brass Typhoon)
threat_intel
APT41 (APT41, Wicked Panda, Brass Typhoon)
# Threat Actor Profile: APT41
ATT&CK ID: G0096
Also known as: APT41, Wicked Panda, Brass Typhoon, BARIUM
Suspected origin: China
## Overview
APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.(Citation: apt41_mandiant) Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.(Citation: FireEye APT41 Aug 2019)(Citation: Group IB APT 41 June 202
Recorded Future
Analyze Recent Atlassian Vulnerabilities and Keep Your Infrastructure Protected
blogs_recorded_future·CVSS 9.6
[CRITICAL] Analyze Recent Atlassian Vulnerabilities and Keep Your Infrastructure Protected
# Analyze Recent Atlassian Vulnerabilities and Keep Your Infrastructure Protected
For years, software solutions built by Atlassian have found their way to nearly every organization's software stack. Tools such as JIRA, Confluence, Bamboo, and BitBucket are often seen playing a crucial role in various departments across enterprises.
From managing projects or handling organization-wide documentation, to hosting the very code of a product being developed by the organization, the constant reliance upon and amount of historical data held within these applications have turned them into a lucrative target for attackers, expanding the attack surface in the process.
## Historical Atlassian Vulnerabilities
Traditionally, vulnerabilities within the Atlassian software stack have originated from di
Greynoiseio
Spike in Atlassian Exploitation Attempts: Patching is Crucial
blogs_greynoiseio
Spike in Atlassian Exploitation Attempts: Patching is Crucial
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
HackerOne
LFI with potential to RCE on ██████ using CVE-2019-3396
hackerone·2019-10-04·CVSS 9.8
CVE-2019-3396 [CRITICAL] LFI with potential to RCE on ██████ using CVE-2019-3396
LFI with potential to RCE on ██████ using CVE-2019-3396
#POC
```
POST /rest/tinymce/1/macro/preview HTTP/1.1
Host: ██████
Content-Type: application/json
Content-Length: 174
{"contentId":"12345","macro":{"name":"widget","body":"","params":{"url":"https://www.youtube.com/watch?v=wHEHYJpCkpg","width":"300","height":"200","_template":"file://../"}}}
```
Thanks,
Ben
## Impact
#
arXiv
Automated Attack Testflow Extraction from Cyber Threat Report using BERT for Contextual Analysis
arxiv_fulltext·2025-07-09
Automated Attack Testflow Extraction from Cyber Threat Report using BERT for Contextual Analysis
IEEEexample:BSTcontrol
Automated Attack Testflow Extraction from Cyber Threat Report using BERT for Contextual Analysis
Faissal Ahmadou1,
Sepehr Ghaffarzadegan1,
Boubakr Nour4,
Makan Pourzandi4,
Mourad Debbabi1,
Chadi Assi1
1Concordia University, Canada
4Ericsson Security Research, Canada
## Abstract
In the ever-evolving landscape of cybersecurity, the rapid identification and mitigation of Advanced Persistent Threats (APTs) is crucial. Security practitioners rely on detailed threat reports to understand the tactics, techniques, and procedures (TTPs) employed by attackers. However, manually extracting attack testflows from these reports requires elusive knowledge and is time-consuming and prone to errors.
This paper proposes , a novel solution leveraging language models ( BERT) and
http://packetstormsecurity.com/files/152568/Atlassian-Confluence-Widget-Connector-Macro-Velocity-Template-Injection.htmlhttp://packetstormsecurity.com/files/161065/Atlassian-Confluence-6.12.1-Template-Injection.htmlhttp://www.rapid7.com/db/modules/exploit/multi/http/confluence_widget_connectorhttps://jira.atlassian.com/browse/CONFSERVER-57974https://www.exploit-db.com/exploits/46731/http://packetstormsecurity.com/files/152568/Atlassian-Confluence-Widget-Connector-Macro-Velocity-Template-Injection.htmlhttp://packetstormsecurity.com/files/161065/Atlassian-Confluence-6.12.1-Template-Injection.htmlhttp://www.rapid7.com/db/modules/exploit/multi/http/confluence_widget_connectorhttps://jira.atlassian.com/browse/CONFSERVER-57974https://www.exploit-db.com/exploits/46731/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-3396
2019-03-25
Published
2021-11-03
Added to CISA KEV
Exploited in the wild