LIVE · cybersecurity feed
Live wire
ai

Say it once: introducing Bot Preference Sync

Cloudflare's new Bot Preference Sync automatically aligns your robots.txt file with your AI bot policies for Search, Agent, and Training. Easily manage which bots access your content without maintaining static files.

zeroday.news ·

Cloudflare has confirmed that it was targeted by the advanced persistent threat (APT) group known as Spook. The attack, which occurred between October 26 and October 30, 2023, involved Spook gaining unauthorized access to Cloudflare's internal Atlassian server. This server hosted Cloudflare's Confluence wiki, Jira bug-tracking system, and Bitbucket source code management system.

Spook exploited a zero-day vulnerability in Atlassian Confluence, identified as CVE-2023-22527, to establish initial access. This vulnerability, a critical authentication bypass, allowed the attackers to create a new administrator account on the Confluence instance. Cloudflare's internal security systems detected the breach on October 30, triggering an immediate response.

Upon detection, Cloudflare's security team, Cloudforce One, initiated an investigation. The company confirmed that the attackers were able to access a limited number of systems. Specifically, Spook gained access to the Atlassian server and, from there, attempted to pivot to Cloudflare's self-hosted GitLab server. The attackers also attempted to access a console server that was not connected to Cloudflare's production network.

Cloudflare stated that the attackers used a "sophisticated social engineering campaign" to obtain credentials, though the specifics of this campaign were not detailed. The company's investigation revealed that the attackers downloaded a limited amount of data, including documentation and source code, from the compromised Atlassian and GitLab instances. However, Cloudflare emphasized that its customer data, production systems, and global network were not impacted by the breach.

The company also confirmed that no customer data, including Cloudflare's network logs, was accessed or exfiltrated. The attackers were unable to gain access to Cloudflare's production network or its global network infrastructure. Cloudflare's security measures, including its use of hardware security keys for authentication, were credited with preventing further lateral movement by the attackers.

Cloudflare has since patched the exploited Confluence vulnerability and implemented additional security enhancements. The company also rotated all potentially compromised credentials and rebuilt the affected systems. Cloudflare's incident response included notifying law enforcement and working with external cybersecurity experts to ensure the integrity of its systems.

Spook, also known as APT41, Blackfly, or Winnti, is a state-sponsored hacking group with a history of targeting technology companies and government entities. The group is known for its sophisticated tactics and its ability to exploit zero-day vulnerabilities. Cloudflare's confirmation of the attack by Spook highlights the ongoing threat posed by advanced persistent threat groups to critical infrastructure and technology providers.

aicloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

OWASP Flags Top AI Skill Risks in New Security Blueprint

The Open Worldwide Application Security Project has a brand-new top 10 security list tailored for the modern era, and it debuts a Universal Skill Format to add consistency and security to the AI add-ons.

ai

AI Is Learning to Write Genetic Code

This sort of research is both exciting and terrifying: The two models in question were told to generate complete genomes for a viable bacteriophage—a type of virus able to infect and replicate itself inside bacteria, destroying them from the inside. Using an existing bacteriophage as an example—ΦX174 (pronounced “fie-ex-1-7-4”), known for its ability to infect and destroy E. coli bacteria—the mode

patch

Friday Squid Blogging: Neon Flying Squid

The neon flying squid can fly in formation. The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the first to capture photographs of such a thing, which looked like the early stages of an alien invasion. They were probably neon flying squid (Ommastrephes bartramii),

security

Lawmakers call for investigation into impact of CISA staffing cuts

Lawmakers say little is known about how recent cuts have impacted CISA and how the knowledge that was lost has been replaced.

breach

Apollo discloses data breach from ongoing wave of attacks hitting financial sector

The private equity firm said attackers broke into some of its cloud platforms during a five-day period in early July, compromising sensitive personal data. The post Apollo discloses data breach from ongoing wave of attacks hitting financial sector appeared first on CyberScoop.

security

Your Shredded Visa Card May Still Work at the Checkout

UMass Amherst researchers showed expired Visa contactless cards can make real purchases by exploiting an unsigned expiry field in Visa’s EMV kernel. Researchers at the University of Massachusetts Amherst demonstrated at USENIX Security 2026 in Baltimore that expired Visa contactless credit cards can complete real purchases, including transactions at live retail and grocery merchants, by […]