Security Flaw in Atlassian Products (Jira, Confluence,Trello, BitBucket) Affecting Multiple Companies
ID: 81b5cb03-06d6-5f60-9509-d8a9fd6603e7
STIX ID: report--81b5cb03-06d6-5f60-9509-d8a9fd6603e7
Feed Name: CloudSEK Blog
Threat Score
CloudSEK reported that Atlassian cloud session cookies remained valid for 30 days and were not invalidated by password changes, enabling attackers who purchase stealer logs and cookies on dark web marketplaces to hijack Jira/Confluence/Bitbucket sessions and bypass 2FA; the report provides PoC steps, marketplace evidence (thousands of compromised machines and hundreds of Atlassian cookies), affected scope, common stealer families, and notes Atlassian has patched the behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
