Cloudflare sheds more light on Thanksgiving security breach in which tokens, source code accessed by suspected spies
ID: e26b0e26-190e-5edb-8738-6b2fee493f91
STIX ID: report--e26b0e26-190e-5edb-8738-6b2fee493f91
Feed Name: The Register (Security)
Cloudflare disclosed that suspected nation-state attackers used credentials and session tokens stolen from an Okta breach to access its internal Atlassian systems (Confluence, Jira, Bitbucket) in late November 2023. The intruders performed reconnaissance, accessed documentation and ~120 code repositories (downloading ~76), installed the Sliver adversary emulation/C2 framework via a Jira plugin to maintain persistence, and searched for secrets and remote-access details; Cloudflare ejected the actors within days, rotated secrets, and conducted a company-wide remediation effort with outside help.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
