Critical Atlassian Flaw Exploited to Deploy Linux Variant of Cerber Ransomware
Threat actors are using unpatched Atlassian servers as a means of distributing the Linux version of the Cerber ransomware, also known as C3RB3R.
The attacks take use of a significant security flaw in the Atlassian Confluence Data Center and Server known as CVE-2023-22518 (CVSS score: 9.1), which enables an unauthorized attacker to reset Confluence and create an administrator account.
With this access, a threat actor could gain complete control over the compromised systems, resulting in the loss of availability, confidentiality, and integrity.
Financially driven cybercrime gangs have been seen misusing the newly formed admin account to install the Effluence web shell plugin and permit the execution of arbitrary commands on the host read more Critical Atlassian Flaw Exploited to De...

