Stealth Bomber: Atlassian Confluence Exploits Drop Web Shells In-Memory
ID: 5474e121-fd9e-5736-9afa-3d35802c77df
STIX ID: report--5474e121-fd9e-5736-9afa-3d35802c77df
Feed Name: Dark Reading
Researchers report active, in-the-wild exploitation of Atlassian Confluence CVE-2023-22527: attackers are using multiple PoCs (including 30 tracked variants) to achieve remote code execution, commonly deploying the Godzilla web shell and newer in-memory web-shell techniques that avoid disk artifacts and increase stealth; unpatched Confluence instances face high compromise risk and defenders are urged to patch, restrict Internet exposure (e.g., behind VPN), and improve network- and memory-based detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
