Zero-Day Exploitation of Atlassian Confluence
ID: e0d657a1-c508-5f57-afec-1ee4ba8a11f9
STIX ID: report--e0d657a1-c508-5f57-afec-1ee4ba8a11f9
Feed Name: Volexity Blog
Threat Score
Volexity investigated active exploitation of a zero-day remote code execution vulnerability in Atlassian Confluence (CVE-2022-26134), identifying an in-memory BEHINDER implant and disk-based webshells (China Chopper and a custom upload shell), recovered attacker commands and IOCs (file hashes and multiple IPs), provided forensic analysis and detection guidance, and recommended immediate patching and mitigation steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
