* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Thursday, July 31, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    Sens. Blackburn, Warnock introduce CREATE Act to provide tax relief to music creators – Yahoo Home

    Sens. Blackburn and Warnock Launch CREATE Act to Deliver Tax Relief for Music Creators

    That’s (Political) Entertainment: When Theatre Meets Politics

    Future Script: How Generative AI Is Changing Collective Bargaining in the Entertainment Industry – Jackson Lewis

    Future Script: How Generative AI Is Transforming Collective Bargaining in Entertainment

    The SBA’s live-entertainment bailout was supposed to end two years ago. We still don’t know how $1.5 billion was spent. – Yahoo Home

    $1.5 Billion Live-Entertainment Bailout: Two Years Later, Where Did the Money Go?

    Wall Street Bets: Caesars, Golden Entertainment, Churchill Downs, GLPI, Boyd – CDC Gaming

    Top Wall Street Bets: Caesars, Golden Entertainment, Churchill Downs, GLPI, and Boyd Take Center Stage

    Micro wrestling coming to NE Ohio – Cleveland.com

    Get Ready, NE Ohio: Micro Wrestling Is Making Its Exciting Debut!

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Cognizant Technology Solutions Corp (CTSH) Q2 2025 Earnings Call Highlights: Strong Revenue … – Yahoo.co

    Cognizant Q2 2025 Earnings: Impressive Revenue Growth and Key Takeaways

    Revving Up The U.S. Technology Engine – Forbes

    Revving Up The U.S. Technology Engine – Forbes

    More than just a hockey player – Rochester Institute of Technology Athletics

    Beyond the Ice: The Inspiring Journey of a Remarkable Athlete from Rochester Institute of Technology

    Smart Logistics in Warehousing – From Legacy Protocols to Green IoT – How Technology Is Reshaping the Sustainable Supply Chain – Logistics Viewpoints –

    Smart Logistics in Warehousing – From Legacy Protocols to Green IoT – How Technology Is Reshaping the Sustainable Supply Chain – Logistics Viewpoints –

    AI’s race in the dark with China – Axios

    The High-Stakes AI Race: Innovation and Competition in the Shadows

    Eagle Unveils Revolutionary X-Ray Technology at Pack Expo

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    Sens. Blackburn, Warnock introduce CREATE Act to provide tax relief to music creators – Yahoo Home

    Sens. Blackburn and Warnock Launch CREATE Act to Deliver Tax Relief for Music Creators

    That’s (Political) Entertainment: When Theatre Meets Politics

    Future Script: How Generative AI Is Changing Collective Bargaining in the Entertainment Industry – Jackson Lewis

    Future Script: How Generative AI Is Transforming Collective Bargaining in Entertainment

    The SBA’s live-entertainment bailout was supposed to end two years ago. We still don’t know how $1.5 billion was spent. – Yahoo Home

    $1.5 Billion Live-Entertainment Bailout: Two Years Later, Where Did the Money Go?

    Wall Street Bets: Caesars, Golden Entertainment, Churchill Downs, GLPI, Boyd – CDC Gaming

    Top Wall Street Bets: Caesars, Golden Entertainment, Churchill Downs, GLPI, and Boyd Take Center Stage

    Micro wrestling coming to NE Ohio – Cleveland.com

    Get Ready, NE Ohio: Micro Wrestling Is Making Its Exciting Debut!

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Cognizant Technology Solutions Corp (CTSH) Q2 2025 Earnings Call Highlights: Strong Revenue … – Yahoo.co

    Cognizant Q2 2025 Earnings: Impressive Revenue Growth and Key Takeaways

    Revving Up The U.S. Technology Engine – Forbes

    Revving Up The U.S. Technology Engine – Forbes

    More than just a hockey player – Rochester Institute of Technology Athletics

    Beyond the Ice: The Inspiring Journey of a Remarkable Athlete from Rochester Institute of Technology

    Smart Logistics in Warehousing – From Legacy Protocols to Green IoT – How Technology Is Reshaping the Sustainable Supply Chain – Logistics Viewpoints –

    Smart Logistics in Warehousing – From Legacy Protocols to Green IoT – How Technology Is Reshaping the Sustainable Supply Chain – Logistics Viewpoints –

    AI’s race in the dark with China – Axios

    The High-Stakes AI Race: Innovation and Competition in the Shadows

    Eagle Unveils Revolutionary X-Ray Technology at Pack Expo

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Atlassian Confluence Server RCE attacks underway from 600+ IPs

January 23, 2024
in Technology
Atlassian Confluence Server RCE attacks underway from 600+ IPs
Share on FacebookShare on Twitter

More than 600 IP addresses are launching thousands of exploit attempts against CVE-2023-22527 – a critical bug in out–of-date versions of Atlassian Confluence Data Center and Server – according to non-profit security org Shadowserver.

Atlassian disclosed the flaw, a template injection flaw that can allow unauthenticated remote code execution (RCE) attacks, last week. The CVE scored a CVSS rating of 10 out of 10, and it affects Confluence Data Center and Server 8 versions released before December 5, 2023 and versions up to 8.4.5.

At the time, the software vendor urged customers to update “immediately” to the latest available version to plug the hole. It appears, however, that not everyone followed this advice.

As of Sunday more than 11,000 instances remain exposed on the internet, and criminals are pounding them with RCE attempts.

In an Xeet on Monday, Shadowserver reported seeing more than 39,000 such attempts since January 19. “Over 600 IPs seen attacking so far (testing callback attempts and ‘whoami’ execution),” the security org revealed, alongside a screenshot showing the security events, IPs and unique ports.

Soon after, internet scanning outfit GreyNoise also reported RCE exploit attempts. “Patch before it’s too late!,” the firm warned.

Patch now: Critical VMware, Atlassian flaws found

Atlassian cranks up the threat meter to max for Confluence authorization flaw

Ivanti and Juniper Networks accused of bending the rules with CVE assignments

Russians invade Microsoft exec mail while China jabs at VMware vCenter Server

Atlassian hasn’t updated its CVE-2023-22527 security advisory to indicate any instances of Confluence Server being under active exploitation. A company spokesperson did not answer The Register’s questions about attempted or successful RCE attacks, and instead emailed the following statement:

Ken Dunham, threat director at cloud security company Qualys’s Threat Research Unit, warned that organizations with any external-facing vulnerable Atlassian instances should “assume a breach,” essentially “treating it as compromised until proven otherwise,” and take precautions. These include patching (in this case by updating to a newer, supported version), plus threat hunting, reviewing logs, monitoring, and auditing the potentially affected systems.

“Attacks like this are easily automated and likely rapidly weaponized to take advantage of vulnerable instances before remediation occurs,” Dunham told The Register.

This latest perfect-10-rated CVE follows a string of critical flaws that have plagued the Australian software developer over recent months. These include four critical bugs, rated 9.0 or higher, that Atlassian alerted customers about last month, via email. However, the warning proved ineffective because the email’s links weren’t live when the message was originally sent.

Then in October, there was an improper authorization vulnerability in Confluence Data Center and Server that initially earned a CVSS score of 9.1 before being upgraded to a 10 after miscreants began exploiting that vulnerability.

Atlassian security may soon become even more challenged: on February 15th the Aussie software company ends support for its Server products, with vastly more expensive Datacenter products or a cloud migration the alternatives. An Atlassian partner recently told The Register that forty percent of its clientele intends to continue using the unsupported products despite Atlassian insisting it won’t provide patches. ®

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : The Register – https://go.theregister.com/feed/www.theregister.com/2024/01/22/atlassian_confluence_server_rce/

Tags: AtlassianConfluencetechnology
Previous Post

Boffins eyeball computer vision costs, find humans are cheaper for oversight chores

Next Post

Robocaller spoofing Joe Biden is telling people not to vote in New Hampshire

New DNA Analysis Allows Scientists To Identify Specific Animals by Their Feces – Smithsonian Institution

Breakthrough DNA Analysis Enables Scientists to Identify Animals Just from Their Feces

July 31, 2025
Some killer whales hunt in pairs to maximize their bounty – Science News

Some killer whales hunt in pairs to maximize their bounty – Science News

July 31, 2025
Be Like Blippi Week – Adventure Science Center

Join the Fun: Be Like Blippi Week at Adventure Science Center!

July 31, 2025
Martha Stewart questions Meghan Markle’s lifestyle brand: ‘Hope she knows what she’s talking about’ – Page Six

Martha Stewart Raises Eyebrows Over Meghan Markle’s Lifestyle Brand: “Hope She Knows What She’s Talking About

July 31, 2025
Trump Executive Order Ends De Minimis Exemption for Rest of World – The New York Times

Trump Executive Order Ends De Minimis Exemption for Rest of World – The New York Times

July 31, 2025
Mexico’s economy grew 0.7% in Q2, outpacing analysts’ forecasts – Mexico News Daily

Mexico’s economy grew 0.7% in Q2, outpacing analysts’ forecasts – Mexico News Daily

July 31, 2025
Sens. Blackburn, Warnock introduce CREATE Act to provide tax relief to music creators – Yahoo Home

Sens. Blackburn and Warnock Launch CREATE Act to Deliver Tax Relief for Music Creators

July 31, 2025
Malnutrition rates reach alarming levels in Gaza, WHO warns – World Health Organization (WHO)

Malnutrition rates reach alarming levels in Gaza, WHO warns – World Health Organization (WHO)

July 31, 2025
Ahead of Trade Deadline, Trump Threatens Canada for Backing Palestinian State – The New York Times

Trump Delivers Stark Warning to Canada Over Backing Palestinian State Ahead of Trade Deadline

July 31, 2025
Cognizant Technology Solutions Corp (CTSH) Q2 2025 Earnings Call Highlights: Strong Revenue … – Yahoo.co

Cognizant Q2 2025 Earnings: Impressive Revenue Growth and Key Takeaways

July 31, 2025

Categories

Archives

July 2025
MTWTFSS
 123456
78910111213
14151617181920
21222324252627
28293031 
« Jun    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (747)
  • Economy (772)
  • Entertainment (21,652)
  • General (16,209)
  • Health (9,809)
  • Lifestyle (780)
  • News (22,149)
  • People (774)
  • Politics (781)
  • Science (15,985)
  • Sports (21,269)
  • Technology (15,751)
  • World (755)

Recent News

New DNA Analysis Allows Scientists To Identify Specific Animals by Their Feces – Smithsonian Institution

Breakthrough DNA Analysis Enables Scientists to Identify Animals Just from Their Feces

July 31, 2025
Some killer whales hunt in pairs to maximize their bounty – Science News

Some killer whales hunt in pairs to maximize their bounty – Science News

July 31, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version