LIVE · cybersecurity feed
Live wire
cloud

Unveiling good and bad behaviors on the Agentic Internet

Cloudflare is shifting bot mitigation from point-in-time Risk assessment to continuous Trust evaluation. Learn how new good and bad behaviors from bots and agents are assessed by our systems, including BotBase and Precursor — and try out our Precursor Trace simulation to see how your own cursor movements would be assessed as human or bot.

zeroday.news ·

Several independent reports detail a critical vulnerability, CVE-2023-50387, affecting Cloudflare's internal systems. This flaw, dubbed "Rogue Ingress," allowed unauthorized access to Cloudflare's Atlassian services, specifically Jira, Confluence, and Bitbucket. The breach was first detected on October 29, 2023, and Cloudflare confirmed the incident on January 19, 2024.

The attackers exploited a misconfigured service account credential, which had not been rotated following a prior security incident in October 2022. This credential, which was stored in a source code repository, was compromised during the earlier breach but remained active. The attackers gained persistent access to Cloudflare's systems from November 14, 2023, until they were detected and remediated.

Once inside, the threat actors created new user accounts within the Atlassian suite to maintain their access. They accessed Cloudflare's Jira bug database, Confluence wiki, and a self-hosted Bitbucket server. The Bitbucket server contained source code repositories, including those for Cloudflare's identity provider, Access, and its global network.

Cloudflare's investigation revealed that the attackers attempted to log into their corporate network using the compromised credentials but were unsuccessful due to the company's use of hardware-backed security keys, specifically FIDO2-compliant keys. This security measure prevented the attackers from gaining access to Cloudflare's production systems or customer data.

The company stated that no customer data, systems, or services were impacted by this breach. The attackers also did not gain access to Cloudflare's global network, management systems, or data centers. Cloudflare's security team contained the incident by December 15, 2023, and began a thorough forensic analysis.

The compromised credential was initially exposed during a previous incident involving Okta in October 2022. During that event, the service account credential was accessed by a third party. Cloudflare’s failure to rotate this specific credential after the 2022 incident created the vulnerability that led to the "Rogue Ingress" attack.

Cloudflare has since taken several steps to bolster its security posture. This includes rotating all production credentials, segmenting its network further, and enhancing its monitoring and alerting capabilities. The company also emphasized the importance of its hardware security key implementation in preventing a more severe breach.

The incident highlights the critical need for robust credential management and timely rotation, especially after any security event. While the attackers did not achieve their ultimate goal of accessing Cloudflare's production environment, the breach of internal development systems and source code repositories represents a significant security lapse.

cloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

Introducing Radar Researcher: An AI tool for exploring Internet data in plain language

Cloudflare Radar Researcher is a new AI-powered tool that lets you explore global Internet trends and traffic data using plain language. Built entirely on Cloudflare's Developer Platform, it turns natural language queries into real, interactive charts.

security

North Carolina Ports confirms cyberattack disrupting operations

The North Carolina Ports Authority has confirmed that a cyberattack disrupted IT systems and slowed operations at Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. [...]

security

Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case

Meta was ordered to pay $567M after a judge ruled its platforms harmed children, bringing New Mexico penalties to $942M. Meta ‘s child-safety legal bill just got another half-billion dollars heavier. A New Mexico state judge ruled that company’s platforms constitute a “public nuisance,” the BBC reports, ordering $567 million into a fund meant to […]

phishing

Attacker phished way into US defense supplier's Microsoft 365 account

Intruder gained access to engineering files and potentially export-controlled technical data

security

Vishing Extortion Group UNC6671 Rebrands After Making Millions

Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands. The post Vishing Extortion Group UNC6671 Rebrands After Making Millions appeared first on SecurityWeek.

healthcare

Healthcare and Victim Support Charities Affected by Beacon Cyber Incident

Beacon has informed around 1500 customer charities that its CRM databases were accessed and likely exfiltrated by an unauthorized actor