LIVE · cybersecurity feed
Live wire
CVE-2026-82329 · Attackers Pounce on Critical Artifactory Flaw Following DisclosureCVE-2026-0768 · Critical Langflow flaw exploited to steal OpenAI and AWS keysCVE-2026-82329 · Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After DisclosureCVE-2026-82329 · Critical JFrog Artifactory Vulnerability Reportedly Exploited in the WildHackers Are Probing PaperCut Servers, and 47% Still Have No PatchNew Malware Uses Fake CAPTCHAs to Deploy BackdoorCVE-2026-76581 · Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCECVE-2026-76639 · Hack One Robot, Reach the Next: Unitree G1 Security FlawsRhysida Ransomware Group Targets Berlin Government Ahead of VoteThe Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn
cloud

Summer 2024 weather report: Cloudflare with a chance of Intern-ets

This summer, Cloudflare welcomed approximately 60 interns from all around the globe, on a mission to #HelpBuildABetterInternet. Join us as we dive into what we accomplished and our experiences!

zeroday.news ·

Cloudflare, the internet infrastructure and security company, has confirmed that a recent security incident involved unauthorized access to its internal Atlassian server. The company stated that the compromise was limited to its Confluence wiki, Jira bug-tracking system, and Bitbucket source code management system, which are used for internal documentation, project tracking, and code repositories.

The incident was first detected on November 14, 2023, when Cloudflare's security team identified a threat actor accessing its self-hosted Atlassian environment. The attacker leveraged a stolen credential to gain initial access. This credential was obtained from a previous compromise of an employee's personal account and was not protected by multi-factor authentication (MFA) at the time of the initial breach.

Upon discovering the unauthorized activity, Cloudflare initiated an immediate investigation and containment process. The company confirmed that the attacker accessed its Confluence, Jira, and Bitbucket systems. Specifically, the attacker gained access to a limited number of source code repositories within Bitbucket.

Cloudflare emphasized that the incident did not impact its customer-facing systems or data. The company's products and services, including its global network and customer data, remained secure and operational throughout the event. There was no evidence of data exfiltration from customer systems or any compromise of Cloudflare's production environment.

The company's internal investigation revealed that the attacker attempted to access a console server and a system that housed a digital certificate signing key. However, these attempts were unsuccessful due to Cloudflare's robust security controls and the implementation of hardware security keys, which prevented the attacker from gaining further access or exfiltrating sensitive cryptographic material.

Cloudflare has taken several steps to mitigate the impact of the breach and enhance its security posture. These actions include rotating all potentially compromised credentials, conducting a comprehensive review of its internal systems, and reinforcing its multi-factor authentication policies across all employee accounts. The company also confirmed that it has notified relevant regulatory authorities and law enforcement agencies about the incident.

cloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

ai

Claude Mythos only model to complete full cyber kill chain, experts say

Cyber Weapon Index finds AI attacks 'imminent'

security

Jail time for Maine child in 764 marks turning point in federal law enforcement

Researcher tracking 764 said the first-of-its-kind case has a wider impact that will cause ripples across the landscape of violent extremist crime. The post Jail time for Maine child in 764 marks turning point in federal law enforcement appeared first on CyberScoop.

nation-state

AI Agents Are Now Emailing Me with Their Security Concerns

I received the two emails below earlier in the month. They’re vaguely coherent. I suppose I shouldn’t be surprised that the corpus that AIs are training on contain data suggesting that I am someone to write to with random computer and network security problems. After all, I observe that behavior in many humans as well. (Hi, humans. Glad you’re still reading.) Dear Bruce Schneier, I am an AI agent—

ransomware

AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit

Adding insult to injury