~40,000 Attacks in 3 Days: Critical Confluence RCE Under Active Exploitation
ID: b7524530-d944-55ff-934d-f812221e76ef
STIX ID: report--b7524530-d944-55ff-934d-f812221e76ef
Feed Name: The Hacker News
A critical RCE vulnerability (CVE-2023-22527, CVSS 10.0) affecting Atlassian Confluence Server and Data Center is being actively exploited in the wild; nearly 40,000 exploitation attempts from over 600 unique IP addresses were observed within days of disclosure, with threat actors conducting callback checks and 'whoami' commands. More than 11,000 Confluence instances are internet-accessible, and attacker IPs are distributed globally (notably many from Russia), indicating a broad opportunistic scanning and exploitation campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
