Cloudflare hacked using auth tokens stolen in Okta attack
ID: daeabb4c-9b24-597f-9723-7c1eab14fce9
STIX ID: report--daeabb4c-9b24-597f-9723-7c1eab14fce9
Feed Name: DataBreaches.Net
Cloudflare disclosed a breach of its self-hosted Atlassian server by a suspected nation-state actor, who accessed Confluence, Jira, and Bitbucket, established persistence via ScriptRunner for Jira, and attempted (unsuccessfully) to access a console server tied to a not-yet-live São Paulo data center. The incident involved reconnaissance, return access on November 22, and interaction with source code management systems, as detailed by Cloudflare leadership and referenced by BleepingComputer.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
