Atlassian has confirmed exploitation of an already addressed Confluence Data Center and Server flaw, tracked as CVE-2023-22518, to facilitate ransomware deployment after a Rapid7 report observed related infections with the Cerber ransomware, which is long believed to be defunct, reports The Record, a news site by cybersecurity firm Recorded Future.
SecurityWeek reports that patches have been released by Veeam to remediate four security vulnerabilities impacting its Veeam ONE IT monitoring and analytics solution.
Cerber ransomware attacks started over the weekend, just days after “critical information” about the now-patched Atlassian Confluence vulnerability was posted online.
Atlassian has urged immediate patching of a critical vulnerability impacting all Confluence Data Center and Confluence Server versions, tracked as CVE-2023-22518, following the emergence of a public exploit that could be exploited to facilitate data wiping attacks, reports BleepingComputer.
The ransomware gang was spotted exploiting the vulnerability just two days after Apache disclosed the flaw and released patched versions of the software.
The Forum of Incident Response and Security Teams (FIRST) published CVSS 4.0 with an eye toward delivering finer granularity around threat intelligence metrics.
Threat actors have launched attacks leveraging a recently patched critical request smuggling flaw in F5's BIG-IP offering, tracked as CVE-2023-46747, just days after the release of a proof-of-concept exploit code, SecurityWeek reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.