logo

Cloudflare sheds more light on Thanksgiving security breach in which tokens, source code accessed by suspected spies

ID: e26b0e26-190e-5edb-8738-6b2fee493f91

STIX ID: report--e26b0e26-190e-5edb-8738-6b2fee493f91

Feed Name: The Register (Security)

Threat Score
88/100

Date Published: 2024-02-02

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

Cloudflare disclosed that suspected nation-state attackers used credentials and session tokens stolen from an Okta breach to access its internal Atlassian systems (Confluence, Jira, Bitbucket) in late November 2023. The intruders performed reconnaissance, accessed documentation and ~120 code repositories (downloading ~76), installed the Sliver adversary emulation/C2 framework via a Jira plugin to maintain persistence, and searched for secrets and remote-access details; Cloudflare ejected the actors within days, rotated secrets, and conducted a company-wide remediation effort with outside help.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.