CVE-2023-22515
published 2023-10-04CVE-2023-22515: Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in…
PriorityP199critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2023-10-13
Exploited in the wild
EPSS
99.16%
99.9th percentile
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances.
Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | >= 8.0.0 < 8.3.3 | 8.3.3 |
| atlassian | confluence_data_center | >= 8.4.0 < 8.4.3 | 8.4.3 |
| atlassian | confluence_data_center | >= 8.5.0 < 8.5.2 | 8.5.2 |
| atlassian | confluence_server | — | — |
| atlassian | confluence_server | — | — |
| atlassian | confluence_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect HTTP GET/POST requests to /server-info.action containing the parameter 'bootstrapStatusProvider.applicationConfig.setupComplete=false' — this is Stage 1 of the exploit chain used to flip the setup completion status and unlock the administrator setup endpoint. ↗
- →Monitor for unauthenticated POST requests to /setup/setupadministrator.action — Stage 2 of the exploit chain attempts to register an attacker-controlled administrator account via this endpoint. ↗
- →Audit Confluence for newly created administrator accounts, especially those created without a corresponding legitimate provisioning event — exploitation results in unauthorized admin account creation. ↗
- →The vulnerability was exploited as a zero-day starting September 14 by threat group tracked as Storm-0062 (also known as DarkShadow and Oro0lxy); threat hunting should include activity from this group on Confluence servers from that date forward. ↗
- →Check Point IPS signature 'Atlassian Confluence Authentication Bypass (CVE-2023-22515)' can be used for network-level detection of exploitation attempts. ↗
- →Qualys WAS QID 150745 is an intrusive detection that exploits vulnerable servers by sending requests to the vulnerable endpoint — use QID 150725 for non-intrusive version-based detection of CVE-2023-22515. ↗
- →Threat actors maintained persistence even after patching was applied — post-patch forensic review of administrator accounts and active sessions is essential. ↗
- ·Atlassian Cloud (atlassian.net-hosted) instances are NOT affected by CVE-2023-22515 — only on-premise Confluence Data Center and Server deployments are vulnerable. ↗
- ·Only Confluence versions 8.0.0 through 8.5.1 are affected; fixed versions are 8.3.3, 8.4.3, and 8.5.2 or later. ↗
- ·Internet-facing (publicly accessible) Confluence instances are at highest risk as the vulnerability is exploitable anonymously without authentication. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.010.0CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g458-xvmc-qg2r: Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerab
ghsa_unreviewed·2023-10-04
CVE-2023-22515 [CRITICAL] CWE-20 GHSA-g458-xvmc-qg2r: Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerab
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances.
Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.
For more details, please review the linked advisory on this CVE.
VulnCheck
Atlassian Confluence Data Center and Server Broken Access Control Vulnerability
vulncheck·2023·CVSS 9.8
CVE-2023-22515 [CRITICAL] Atlassian Confluence Data Center and Server Broken Access Control Vulnerability
Atlassian Confluence Data Center and Server Broken Access Control Vulnerability
Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence.
Affected: Atlassian Confluence Server and Data Center
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Check all affected Confluence instances for evidence of compromise per vendor instructions and report any positive findings to CISA.
Known Ransomware Campaign Use: Known
Exploitation References: https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html;
CISA
Atlassian Confluence Data Center and Server Broken Access Control Vulnerability
cisa·2023-10-05·CVSS 9.8
CVE-2023-22515 [CRITICAL] Atlassian Confluence Data Center and Server Broken Access Control Vulnerability
Vulnerability: Atlassian Confluence Data Center and Server Broken Access Control Vulnerability
Affected: Atlassian Confluence Data Center and Server
Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Check all affected Confluence instances for evidence of compromise per vendor instructions and report any positive findings to CISA.
Notes: https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html; https://nvd.nist.gov/vuln/detail/CVE-2023-
Atlassian
CVE-2023-22515 - Broken Access Control Vulnerability in Confluence Data Center and Server
vendor_atlassian·CVSS 9.8
CVE-2023-22515 [CRITICAL] CVE-2023-22515 - Broken Access Control Vulnerability in Confluence Data Center and Server
CVE-2023-22515 - Broken Access Control Vulnerability in Confluence Data Center and Server
CVE-2023-22515 - Broken Access Control Vulnerability in Confluence Data Center and Server
CVE: CVE-2023-22515
Affected products: Confluence Data Center
Suricata
ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22515 Vulnerable Server Detected M2
suricata·2023-10-12·CVSS 9.8
CVE-2023-22515 [CRITICAL] ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22515 Vulnerable Server Detected M2
ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22515 Vulnerable Server Detected M2
Rule: alert http [$HOME_NET,$HTTP_SERVERS] any -> any any (msg:"ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22515 Vulnerable Server Detected M2"; flow:established,to_client; http.response_body; content:"|3c|li|20|class|3d 22|print|2d|only|22 3e|Printed|20|by|20|Atlassian|20|Confluence|20|8|2e|"; fast_pattern; pcre:"/^(?:0\.[01234]|1\.[0134]|2\.[0123]|3\.[012]|4\.[012]|5\.[01])\x3c/R"; threshold:type limit, count 1, seconds 3600, track by_src; reference:url,confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html; reference:url,www.rapid7.com/blog/post/2023/10/04/etr-cve-2023-22515-zero-day-privilege-escalation-in-conf
Suricata
ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22515 Step 2/2 Attempt
suricata·2023-10-12·CVSS 9.8
CVE-2023-22515 [CRITICAL] ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22515 Step 2/2 Attempt
ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22515 Step 2/2 Attempt
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22515 Step 2/2 Attempt"; flow:established,to_server; flowbits:set,ET.CVE-2023-22515.step2.request; http.method; content:"POST"; http.uri; content:"/setup/setupadministrator.action"; fast_pattern; http.header; content:"X-Atlassian-Token"; nocase; content:"|3a 20|no-check"; within:10; http.request_body; content:"username="; content:"password="; reference:url,confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html; reference:url,www.rapid7.com/blog/post/2023/10/04/etr-cve-2023-22515-zero-day-privilege-escalation-in-confluence-
Suricata
ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22515 Step 1/2 Attempt
suricata·2023-10-12·CVSS 9.8
CVE-2023-22515 [CRITICAL] ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22515 Step 1/2 Attempt
ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22515 Step 1/2 Attempt
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22515 Step 1/2 Attempt"; flow:established,to_server; flowbits:set,ET.CVE-2023-22515.step1.request; http.uri; content:"/server-info.action?"; content:"bootstrapStatusProvider.applicationConfig.setupComplete=false"; distance:0; fast_pattern; reference:url,confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html; reference:url,www.rapid7.com/blog/post/2023/10/04/etr-cve-2023-22515-zero-day-privilege-escalation-in-confluence-server-and-data-center/; reference:url,attackerkb.com/topics/Q5f0ItSzw5/cve-2023-22515/rapid7-analysis; r
Suricata
ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22515 Vulnerable Server Detected M1
suricata·2023-10-12·CVSS 9.8
CVE-2023-22515 [CRITICAL] ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22515 Vulnerable Server Detected M1
ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22515 Vulnerable Server Detected M1
Rule: alert http [$HOME_NET,$HTTP_SERVERS] any -> any any (msg:"ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22515 Vulnerable Server Detected M1"; flow:established,to_client; http.response_body; content:"|3c|meta|20|name|3d 22|ajs|2d|version|2d|number|22 20|content|3d 22|8|2e|"; fast_pattern:23,20; pcre:"/^(?:0\.[01234]|1\.[0134]|2\.[0123]|3\.[012]|4\.[012]|5\.[01])\x22/R"; threshold:type limit, count 1, seconds 3600, track by_src; reference:url,confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html; reference:url,www.rapid7.com/blog/post/2023/10/04/etr-cve-2023-22515-zero-day-privilege-escalation-in-confluence-serve
Suricata
ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22515 Step 2/2 Success
suricata·2023-10-12·CVSS 9.8
CVE-2023-22515 [CRITICAL] ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22515 Step 2/2 Success
ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22515 Step 2/2 Success
Rule: alert http [$HOME_NET,$HTTP_SERVERS] any -> any any (msg:"ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22515 Step 2/2 Success"; flow:established,to_client; flowbits:isset,ET.CVE-2023-22515.step2.request; http.stat_code; content:"302"; http.location; bsize:25; content:"/setup/finishsetup.action"; fast_pattern; reference:url,confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html; reference:url,www.rapid7.com/blog/post/2023/10/04/etr-cve-2023-22515-zero-day-privilege-escalation-in-confluence-server-and-data-center/; reference:url,attackerkb.com/topics/Q5f0ItSzw5/cve-2023-22515/rapid7-analysis; reference:cve,2023-22515; referen
Suricata
ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22515 Step 1/2 Success
suricata·2023-10-12·CVSS 9.8
CVE-2023-22515 [CRITICAL] ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22515 Step 1/2 Success
ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22515 Step 1/2 Success
Rule: alert http [$HOME_NET,$HTTP_SERVERS] any -> any any (msg:"ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22515 Step 1/2 Success"; flow:established,to_client; flowbits:isset,ET.CVE-2023-22515.step1.request; http.stat_code; content:"200"; http.response_body; content:"|3c 2f|div|3e 3c 21 2d 2d 20 5c 23|sidebar|2d|container|20 2d 2d 3e 0a 0a 20 20 20 20 20 20 20 20|success|0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f|main|3e 3c 21 2d 2d 20 5c 23|main|20 2d 2d 3e 0a|"; fast_pattern; reference:url,confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html; reference:url,www.rapid7.com/blog/post/2023/10/04/etr-cve-2023-22515-zero-day-pr
Exploit-DB
Atlassian Confluence Data Center and Server - Authentication Bypass (Metasploit)
exploitdb·2024-02-27·CVSS 9.8
[CRITICAL] Atlassian Confluence Data Center and Server - Authentication Bypass (Metasploit)
Atlassian Confluence Data Center and Server - Authentication Bypass (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule 'Atlassian Confluence Data Center and Server Authentication Bypass via Broken Access Control',
'Description' => %q{
This module exploits a broken access control vulnerability in Atlassian Confluence servers leading to an authentication bypass.
A specially crafted request can be create new admin account without authentication on the target Atlassian server.
},
'Author' => [
'Unknown', # exploited in the wild
'Emir Polat' # metasploit module
],
'References' => [
['CVE', '2023-22515'],
['URL', 'https://confluence.atlassian.com/security/cve-2023-225
Metasploit
Atlassian Confluence Data Center and Server Authentication Bypass via Broken Access Control
metasploit
Atlassian Confluence Data Center and Server Authentication Bypass via Broken Access Control
Atlassian Confluence Data Center and Server Authentication Bypass via Broken Access Control
This module exploits a broken access control vulnerability in Atlassian Confluence servers leading to an authentication bypass. A specially crafted request can be create new admin account without authentication on the target Atlassian server.
Nuclei
Atlassian Confluence - Privilege Escalation
nuclei·CVSS 9.8
CVE-2023-22515 [CRITICAL] Atlassian Confluence - Privilege Escalation
Atlassian Confluence - Privilege Escalation
Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence.
Template:
id: CVE-2023-22515
info:
name: Atlassian Confluence - Privilege Escalation
author: s1r1us,iamnoooob,rootxharsh,pdresearch
severity: critical
description: |
Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence.
impact: |
Unauthenticated attackers can exploit broken access control to create unauthorized Confluence administrator accounts and gain complete administrative access to Atlassian Confluence insta
Metasploit
Atlassian Confluence Unauthenticated Remote Code Execution
metasploit
Atlassian Confluence Unauthenticated Remote Code Execution
Atlassian Confluence Unauthenticated Remote Code Execution
This module exploits an improper input validation issue in Atlassian Confluence, allowing arbitrary HTTP parameters to be translated into getter/setter sequences via the XWorks2 middleware and in turn allows for Java objects to be modified at run time. The exploit will create a new administrator user and upload a malicious plugins to get arbitrary code execution. All versions of Confluence between 8.0.0 through to 8.3.2, 8.4.0 through to 8.4.2, and 8.5.0 through to 8.5.1 are affected.
Tenable
Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
blogs_tenable·2026-05-27
CVE-2023-4966 Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
## Exposure Management
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
Tenable Research has developed a graph-based model linking 600+ threat groups to real-world customer exposures. It reveals which vulnerabilities sit at the intersection of severity, active exploit
Greynoiseio
GreyNoise Detects Active Exploitation of CVEs Mentioned in Black Basta’s Leaked Chat Logs
blogs_greynoiseio·2025-02-26·CVSS 9.8
[CRITICAL] GreyNoise Detects Active Exploitation of CVEs Mentioned in Black Basta’s Leaked Chat Logs
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Qualys
Defense Lessons From the Black Basta Ransomware Playbook
blogs_qualys·2025-02-25
Defense Lessons From the Black Basta Ransomware Playbook
## Table of Contents
Know Your Enemys Playbook
Attackers Move Fast
How Qualys Can Help
The cybersecurity world was rocked last week by a massive leak of Black Basta’s internal communications that emerged from the group’s chat logs. Triggered by internal conflicts and a retaliatory data dump following attacks on Russian banks, the exposed records offer a rare glimpse into Black Basta’s tactics, operations, and leadership.
We’ve analyzed these newly unveiled tactics, and in this blog, we equip security teams with clear, actionable insights. We aim to highlight the key lessons learned—like immediate patching, tighter access controls, and rapid incident response—and provide an urgent call to action. This practical guide aims to help organizations strengthen their defenses against evolving
Qualys
Defense Lessons From the Black Basta Ransomware Playbook | Qualys
blogs_qualys·2025-02-25
Defense Lessons From the Black Basta Ransomware Playbook | Qualys
#### Table of Contents
- Know Your Enemys Playbook
- Attackers Move Fast
- How Qualys Can Help
The cybersecurity world was rocked last week by a massive leak of Black Basta’s internal communications that emerged from the group’s chat logs. Triggered by internal conflicts and a retaliatory data dump following attacks on Russian banks, the exposed records offer a rare glimpse into Black Basta’s tactics, operations, and leadership.
We’ve analyzed these newly unveiled tactics, and in this blog, we equip security teams with clear, actionable insights. We aim to highlight the key lessons learned—like immediate patching, tighter access controls, and rapid incident response—and provide an urgent call to action. This practical guide aims to help organizations strengthen their defenses against ev
Dfir Report
Confluence Exploit Leads to LockBit Ransomware
blogs_dfir_report·2025-02-24·CVSS 9.8
[CRITICAL] Confluence Exploit Leads to LockBit Ransomware
From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion Read More
- dragonforce Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs Read More
Services Overview
Threat Hunting
-
Integration
CTI Program Advisory
Incident Response Playbook
About us
Contact Us
Collaboration
Careers
Analysts
Access DFIR Labs
Get in Touch
Public Reports
Products Overview
Threat intel Overview
Threat Feed
Private DFIR Reports
All Intel
Active Defense
DFIR Labs
Case Artifacts
Detection Pack
AI Training Ground
Service Overview
Threat Hunting
Integration
CTI Program Advisory
Incident Response Playbook
Company Overview
About us
Contact Us
Careers
Analyst
SQL Brute Force Leads to BlueSky Ransomware
From OneNote to RansomNote: An Ice Col
Sentinelone
RansomHub
blogs_sentinelone·2025-01-08
RansomHub
How It Works The Singularity XDR Difference
Singularity Marketplace One-Click Integrations to Unlock the Power of XDR
Pricing & Packaging Comparisons and Guidance at a Glance
Purple AI Accelerate SecOps with Generative AI
Singularity Hyperautomation Easily Automate Security Processes
AI-SIEM The AI SIEM for the Autonomous SOC
Singularity Data Lake AI-Powered, Unified Data Lake
Singularity Data Lake for Log Analytics Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
Singularity Endpoint Autonomous Prevention, Detection, and Response
Singularity XDR Native & Open Protection, Detection, and Response
Singularity RemoteOps Forensics Orchestrate Forensics at Scale
Singularity
Threat Intelligence Comprehensive Adversary Intelligence
Singularity Vulnerability Management
Bleepingcomputer
FBI, CISA, and NSA reveal most exploited vulnerabilities of 2023
blogs_bleepingcomputer·2024-11-12·CVSS 10.0
[CRITICAL] FBI, CISA, and NSA reveal most exploited vulnerabilities of 2023
## FBI, CISA, and NSA reveal most exploited vulnerabilities of 2023
## Sergiu Gatlan
The FBI, the NSA, and Five Eyes cybersecurity authorities have released a list of the top 15 routinely exploited vulnerabilities throughout last year, most of them first abused as zero-days.
A joint advisory published on Tuesday calls for organizations worldwide to immediately patch these security flaws and deploy patch management systems to minimize their networks' exposure to potential attacks.
"In 2023, malicious cyber actors exploited more zero-day vulnerabilities to compromise enterprise networks compared to 2022, allowing them to conduct cyber operations against higher-priority targets," the cybersecurity agencies warned .
"In 2023, the majority of the most frequently exploited vulnerabilities
Tenable
Cybersecurity Snapshot: RansomHub Group Triggers CISA Warning, While FBI Says North Korean Hackers Are Targeting Crypto Orgs
blogs_tenable·2024-09-06
Cybersecurity Snapshot: RansomHub Group Triggers CISA Warning, While FBI Says North Korean Hackers Are Targeting Crypto Orgs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
Combine Qualys TruRisk™ and MITRE ATT&CK to Adopt Threat-Informed Defense to Reduce Risk
blogs_qualys·2024-03-25
Combine Qualys TruRisk™ and MITRE ATT&CK to Adopt Threat-Informed Defense to Reduce Risk
## Table of Contents
Announcing MITRE ATT&CK Matrix Prioritization in Qualys VMDR
MITRE ATT&CK Framework
Top MITRE ATT&CK Tactics and Techniques Leveraged
How to Combine Qualys TruRisk and MITRE ATT&CK to Reduce Your Cyber Risk
Using the MITRE ATT&CK Matrix for Prioritization
Remediation Strategies
Conclusion
Contributors
There are so many vulnerabilities disclosed daily that no one can patch all of them. Unfortunately, attackers can exploit them while you are still in the process of reviewing, prioritizing, and patching. Effective risk-based prioritization focuses your limited resources and remediation efforts where you will have the greatest impact in reducing risk and safeguarding your assets.
While CVSS and EPSS are foundational metrics for risk severity, they can miss real t
Qualys
Combine Qualys TruRisk™ and MITRE ATT&CK to Adopt Threat-Informed Defense to Reduce Risk | Qualys
blogs_qualys·2024-03-25
Combine Qualys TruRisk™ and MITRE ATT&CK to Adopt Threat-Informed Defense to Reduce Risk | Qualys
#### Table of Contents
- Announcing MITRE ATT&CK Matrix Prioritization in Qualys VMDR
- MITRE ATT&CK Framework
- Top MITRE ATT&CK Tactics and Techniques Leveraged
- How to Combine Qualys TruRisk and MITRE ATT&CK to Reduce Your Cyber Risk
- Using the MITRE ATT&CK Matrix for Prioritization
- Remediation Strategies
- Conclusion
- Contributors
There are so many vulnerabilities disclosed daily that no one can patch all of them. Unfortunately, attackers can exploit them while you are still in the process of reviewing, prioritizing, and patching. Effective risk-based prioritization focuses your limited resources and remediation efforts where you will have the greatest impact in reducing risk and safeguarding your assets.
While CVSS and EPSS are foundational metrics for risk severity, they can
Unit42
Ransomware Retrospective 2024: Unit 42 Leak Site Analysis
blogs_unit42·2024-02-05
Ransomware Retrospective 2024: Unit 42 Leak Site Analysis
## Executive Summary
The ransomware landscape experienced significant transformations and challenges in 2023. The year saw a 49% increase in victims reported by ransomware leak sites, with a total of 3,998 posts from various ransomware groups.
What drove this surge of activity? 2023 saw high-profile vulnerabilities like SQL injection for MOVEit and GoAnywhere MFT services. Zero-day exploits for these vulnerabilities drove spikes in ransomware infections by groups like CL0P, LockBit and ALPHV (BlackCat) before defenders could update the vulnerable software.
Leak site data reveals at least 25 new ransomware groups emerged in 2023, indicating the continued attraction of ransomware as a profitable criminal activity. Despite the appearance of new groups such as Darkrace, CryptNet and U-Bomb,
Unit42
Ransomware Retrospective 2024: Unit 42 Leak Site Analysis
blogs_unit42·2024-02-05
Ransomware Retrospective 2024: Unit 42 Leak Site Analysis
Threat Research Center
Threat Research
Ransomware
## Ransomware Retrospective 2024: Unit 42 Leak Site Analysis
Doel Santos
Published: February 5, 2024
Cybercrime
Ransomware
Threat Research
Trend Reports
ALPHV
Ambitious Scorpius
Blackcat
Buzzing Scorpius
Hive
Ignoble Scorpius
Leak site
Ragnar Locker
Ransomed
Ransomed.Vc
Royal Ransomware
Salty Scorpius
Trigona
Vice Society
## Executive Summary
The ransomware landscape experienced significant transformations and challenges in 2023. The year saw a 49% increase in victims reported by ransomware leak sites, with a total of 3,998 posts from various ransomware groups.
What drove this surge of activity? 2023 saw high-profile vulnerabilities like SQL injection for MOVEit and GoAnywhere MFT services. Zero-day exploits fo
Tenable
CVE-2023-22527: Atlassian Confluence Data Center and Server Template Injection Exploited in the Wild
blogs_tenable·2024-01-23·CVSS 9.8
[CRITICAL] CVE-2023-22527: Atlassian Confluence Data Center and Server Template Injection Exploited in the Wild
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
Atlassian Confluence Broken Access Control Vulnerability (CVE-2023-22515)
blogs_qualys·2023-11-15·CVSS 9.8
CVE-2023-22515 [CRITICAL] Atlassian Confluence Broken Access Control Vulnerability (CVE-2023-22515)
## Table of Contents
About CVE-2023-22515
Exploitation Overview
Vulnerability Analysis
Detecting the Vulnerability with Qualys WAS
Qualys WAS Report
Solution & Mitigation
Credits
Atlassian issued an Advisory on October 4, 2023 , for CVE-2023-22515 , a critical severity vulnerability affecting Confluence Server and Data Center. According to the advisory, the vulnerability was initially published as a Privilege Escalation vulnerability but was later updated to a Broken Access Control Vulnerability, Atlassian has also rated the vulnerability with 10 CVSS score. On October 5, 2023, the vulnerability was included in “CISA’s Known Exploited Vulnerabilities Catalog” .
Qualys Web Application Scanning released two QIDs, 150725 & 150745 , to address CVE-2023-22515.
QID 150725 was released
Qualys
Atlassian Confluence (CVE-2023-22515): Broken Access Control Bug | Qualys
blogs_qualys·2023-11-15·CVSS 9.8
CVE-2023-22515 [CRITICAL] Atlassian Confluence (CVE-2023-22515): Broken Access Control Bug | Qualys
#### Table of Contents
- About CVE-2023-22515
- Exploitation Overview
- Vulnerability Analysis
- Detecting the Vulnerability with Qualys WAS
- Qualys WAS Report
- Solution & Mitigation
- Credits
Atlassian issued an Advisory on October 4, 2023, for CVE-2023-22515, a critical severity vulnerability affecting Confluence Server and Data Center. According to the advisory, the vulnerability was initially published as a Privilege Escalation vulnerability but was later updated to a Broken Access Control Vulnerability, Atlassian has also rated the vulnerability with 10 CVSS score. On October 5, 2023, the vulnerability was included in “CISA’s Known Exploited Vulnerabilities Catalog”.
Qualys Web Application Scanning released two QIDs, 150725 & 150745, to address CVE-2023-22515.
QID 150725 was rel
Tenable
CVE-2023-22518: Critical Atlassian Confluence Data Center and Server Improper Authorization Vulnerability
blogs_tenable·2023-11-03·CVSS 9.8
[CRITICAL] CVE-2023-22518: Critical Atlassian Confluence Data Center and Server Improper Authorization Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Wiz
Crying Out Cloud - November Newsletter | Wiz
blogs_wiz·2023-11-01·CVSS 9.8
CVE-2023-42115 [CRITICAL] Crying Out Cloud - November Newsletter | Wiz
The past month has brought a series of vulnerabilities and security incidents that have left users affected. Amidst the noise, we've taken it upon ourselves to curate the most significant developments for you.
Here are our top picks of cloud security highlights!
## 🐞 High Profile Vulnerabilities
## Critical and high severity 0day vulnerabilities in Exim
Multiple vulnerabilities were disclosed in Exim Mail Transfer Agent (MTA), including CVE-2023-42115, which is a critical vulnerability enabling unauthenticated attackers to remotely execute code on publicly exposed Exim servers with a specific non-default configuration. This issue results from improper input validation that leads to writing arbitrary code past the end of the buffer.
According to Wiz data, although Exim is very prevalen
Bleepingcomputer
Atlassian warns of critical Confluence flaw leading to data loss
blogs_bleepingcomputer·2023-10-31·CVSS 9.8
CVE-2023-22518 [CRITICAL] Atlassian warns of critical Confluence flaw leading to data loss
## Atlassian warns of critical Confluence flaw leading to data loss
## Sergiu Gatlan
Australian software company Atlassian warned admins to immediately patch Internet-exposed Confluence instances against a critical security flaw that could lead to data loss following successful exploitation.
Described as an improper authorization vulnerability affecting all versions of Confluence Data Center and Confluence Server software, the bug is tracked as CVE-2023-22518 and puts publicly accessible instances at critical risk.
While threat actors could use the flaw to destroy data on affected servers, the bug doesn't impact confidentiality as it can't be exploited to exfiltrate instance data. Atlassian Cloud sites accessed via an atlassian.net domain are also unaffected by this vulnerability.
"As
Checkpoint
23rd October – Threat Intelligence Report
blogs_checkpoint·2023-10-23
CVE-2023-22515 23rd October – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 23rd October – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 23rd October, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Attackers have gained access to parts of the network of the cloud identity authentication giant Okta. The hackers managed to gain access to the firm’s support unit for at least two weeks and have attempted to use tokens copied from support tickets to access the firm’s customers’ networks. Reportedly, the firm only became
Bleepingcomputer
Ukrainian activists hack Trigona ransomware gang, wipe servers
blogs_bleepingcomputer·2023-10-18·CVSS 9.8
[CRITICAL] Ukrainian activists hack Trigona ransomware gang, wipe servers
## Ukrainian activists hack Trigona ransomware gang, wipe servers
## Ionut Ilascu
A group of cyber activists under the Ukrainian Cyber Alliance banner has hacked the servers of the Trigona ransomware gang and wiped them clean after copying all the information available.
The Ukrainian Cyber Alliance fighters say they exfiltrated all of the data from the threat actor’s systems, including source code and database records, which may include decryption keys.
## Trigona ransomware out of commission
Ukrainian Cyber Alliance hackers gained access to Trigona ransomware’s infrastructure by using a public exploit for CVE-2023-22515, a critical vulnerability in Confluence Data Center and Server that can be leveraged remotely to escalate privileges.
The vulnerability was leveraged in attacks as a
Bleepingcomputer
CISA, FBI urge admins to patch Atlassian Confluence immediately
blogs_bleepingcomputer·2023-10-16·CVSS 9.8
CVE-2023-22515 [CRITICAL] CISA, FBI urge admins to patch Atlassian Confluence immediately
## CISA, FBI urge admins to patch Atlassian Confluence immediately
## Sergiu Gatlan
CISA, FBI, and MS-ISAC warned network admins today to immediately patch their Atlassian Confluence servers against a maximum severity flaw actively exploited in attacks.
Tracked as CVE-2023-22515 , this critical privilege escalation flaw affects Confluence Data Center and Server 8.0.0 and later and is remotely exploitable in low-complexity attacks that don't require user interaction.
On October 4, when it released security updates, Atlassian advised customers to upgrade their Confluence instances as soon as possible to one of the fixed versions (i.e., 8.3.3 or later, 8.4.3 or later, 8.5.2 or later) as the bug was already exploited in the wild as a zero-day.
Those who couldn't upgrade were urged to shut
Bleepingcomputer
Microsoft: State hackers exploiting Confluence zero-day since September
blogs_bleepingcomputer·2023-10-11·CVSS 9.8
[CRITICAL] Microsoft: State hackers exploiting Confluence zero-day since September
## Microsoft: State hackers exploiting Confluence zero-day since September
## Bill Toulas
Considering that Atlassian made security updates available in early October, Storm-0062 exploited the flaw as a zero-day bug for nearly three weeks, creating arbitrary administrator accounts on exposed endpoints.
Storm-0062 is a state hacking group linked to China's Ministry of State Security and known for targeting software, engineering, medical research, government, defense, and tech firms in the U.S., U.K., Australia, and various European countries to collect intelligence.
The United States charged the Chinese hackers in July 2020 for stealing terabytes of data by hacking government organizations and companies worldwide.
## PoC exploit released online
According to data collected by cybersecur
Checkpoint
9th October – Threat Intelligence Report
blogs_checkpoint·2023-10-09
CVE-2023-4863 9th October – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 9th October – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 9th October, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The American Rock County Public Health Department, which serves more than 160K people across Wisconsin area, has been a victim of a ransomware attack that forced officials to take some systems offline. Cuba ransomware gang has claimed responsibility for the attack, claiming to have stolen financial documents, tax informatio
Bleepingcomputer
Atlassian patches critical Confluence zero-day exploited in attacks
blogs_bleepingcomputer·2023-10-04·CVSS 9.8
[CRITICAL] Atlassian patches critical Confluence zero-day exploited in attacks
## Atlassian patches critical Confluence zero-day exploited in attacks
## Sergiu Gatlan
Australian software company Atlassian released emergency security updates to fix a maximum severity zero-day vulnerability in its Confluence Data Center and Server software, which has been exploited in attacks.
"Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances," the company said .
"Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is no
Tenable
CVE-2023-22515: Zero-Day Vulnerability in Atlassian Confluence Data Center and Server Exploited in the Wild
blogs_tenable·2023-10-04·CVSS 9.8
[CRITICAL] CVE-2023-22515: Zero-Day Vulnerability in Atlassian Confluence Data Center and Server Exploited in the Wild
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Sentinelone
RansomHub
blogs_sentinelone
RansomHub
## RansomHub Ransomware: In-Depth Analysis, Detection, and Mitigation
## What Is RansomHub Ransomware?
RansomHub operations were first observed in February of 2024. Since then, the group has drawn heavily upon its ability to recruit and attract operators from other, sometimes imploding, extortion operations. Upon the collapse of ALPHV, for example, multiple affiliates migrated to RansomHub, hoping to monetize their stolen data through them. RansomHub has been associated with the re-extortion of ransomware victims, including high-value healthcare organizations. Primary operators behind RansomHub have openly recruited affiliates from other ransomware operations via their various communication channels, including DLS sites, forum posts, and Telegram.
Operating primarily as a Ransomware-as-
Greynoiseio
CVE-2023-22515: Critical Privilege Escalation Vulnerability in Atlassian's Confluence
blogs_greynoiseio·CVSS 9.8
[CRITICAL] CVE-2023-22515: Critical Privilege Escalation Vulnerability in Atlassian's Confluence
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Greynoiseio
NoiseLetter
blogs_greynoiseio·CVSS 10.0
[CRITICAL] NoiseLetter
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Greynoiseio
The Fifth Day Of Tagsmas (2023): Unauthorized Admin Accounts on Atlassian Confluence Server and Data Center (CVE-2023-22515)
blogs_greynoiseio·CVSS 9.8
[CRITICAL] The Fifth Day Of Tagsmas (2023): Unauthorized Admin Accounts on Atlassian Confluence Server and Data Center (CVE-2023-22515)
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Threat Intel
Ukrainian Cyber Alliance
threat_intel·CVSS 9.8
CVE-2023-22515 [CRITICAL] Ukrainian Cyber Alliance
# Threat Actor: Ukrainian Cyber Alliance
## Description
Cyber Alliance is a hacktivist group that has demonstrated capabilities in exploiting vulnerabilities, such as CVE-2023-22515 in Confluence, to escalate privileges and access targeted infrastructure. They successfully accessed Trigona's systems, exfiltrating sensitive data and ultimately defacing and deleting the organization's site.
Greynoiseio
Spike in Atlassian Exploitation Attempts: Patching is Crucial
blogs_greynoiseio
Spike in Atlassian Exploitation Attempts: Patching is Crucial
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
arXiv
Efficacy of EPSS in High Severity CVEs found in KEV
arxiv_fulltext·2024-11-04
Efficacy of EPSS in High Severity CVEs found in KEV
empty
empty
24pt
10pt plus 1.0pt minus 2.0pt
## Abstract
The Exploit Prediction Scoring System (EPSS) is designed to assess the probability of a vulnerability being exploited in the next 30 days relative to other vulnerabilities. The latest version, based on a research paper published in arXiv , assists defenders in deciding which vulnerabilities to prioritize for remediation. This study evaluates EPSS's ability to predict exploitation before vulnerabilities are actively compromised, focusing on high severity CVEs that are known to have been exploited and included in the CISA KEV catalog. By analyzing EPSS score history, the availability and simplicity of exploits, the system's purpose, its value as a target for Threat Actors (TAs), this paper examines EPSS's potential and identifies ar
http://packetstormsecurity.com/files/175225/Atlassian-Confluence-Unauthenticated-Remote-Code-Execution.htmlhttps://confluence.atlassian.com/display/KB/FAQ+for+CVE-2023-22515https://confluence.atlassian.com/pages/viewpage.action?pageId=1295682276https://jira.atlassian.com/browse/CONFSERVER-92475http://packetstormsecurity.com/files/175225/Atlassian-Confluence-Unauthenticated-Remote-Code-Execution.htmlhttps://confluence.atlassian.com/display/KB/FAQ+for+CVE-2023-22515https://confluence.atlassian.com/pages/viewpage.action?pageId=1295682276https://jira.atlassian.com/browse/CONFSERVER-92475https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-22515
2023-10-04
Published
2023-10-05
Added to CISA KEV
Exploited in the wild