LIVE · cybersecurity feed
Live wire
cloud

Welcome to Agents Week

Agents Week explores how cloud infrastructure must evolve to serve autonomous agents rather than human browsers. Join us as we unpack the storage, execution, and security primitives needed for an agent-native web.

zeroday.news · 3h ago

Cloudflare has confirmed a security incident involving unauthorized access to its internal Atlassian server, which hosts its Confluence wiki, Jira bug-tracking system, and Bitbucket source code management. The company stated that a suspected state-sponsored attacker gained access to the server on October 14, 2023, by compromising an employee's credentials.

The attacker reportedly used these compromised credentials to access a Cloudflare employee account, which did not have multi-factor authentication (MFA) enabled. This initial access allowed the threat actor to pivot to the internal Atlassian server. Cloudflare indicated that the attacker attempted to access a console server and its Atlassian systems on October 26, but these attempts were blocked.

On November 22, the attacker successfully accessed the Atlassian server. Cloudflare detected the breach on November 24 and initiated an investigation. The company subsequently rotated over 5,000 production credentials, segmented its internal Atlassian server from its corporate network, and reset credentials for all employees.

According to Cloudflare, the attacker accessed its Confluence wiki and Jira systems, and also gained access to its Bitbucket source code repositories. The company reported that the attacker downloaded 76 repositories, including those containing system architecture diagrams, database schemas, and information about its identity and access management. Cloudflare emphasized that no customer data or systems were impacted by this breach.

The company's investigation revealed that the attacker had been persistent, attempting to establish a foothold in Cloudflare's network for several months. The threat actor reportedly used a stolen credential to access Cloudflare's systems, targeting a specific employee. Cloudflare has not publicly identified the state-sponsored group responsible for the attack, but the company's security team is actively collaborating with law enforcement agencies on the ongoing investigation.

Cloudflare has stated that the incident did not compromise its global network, its edge network, or any customer-facing services. The company has also confirmed that its core infrastructure, including its DNS, CDN, and security services, remained secure and operational throughout the incident. Cloudflare has committed to providing further updates as its investigation progresses.

cloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

SabPaisa Partners with AccuKnox for Zero Trust AI-Powered Cloud Security to Secure Its Payments Platform

CALIFORNIA, USA, 2nd August 2026, CyberNewswire

security

Google Chrome may soon block New Tab hijacker extensions by default

Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. [...]

breach

Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC released

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Nono: Open-source sandbox for AI agents AI coding agents run with the same permissions as their users, meaning they can access sensitive files, credentials, and production systems. A prompt injection, hallucinated command, or simple mistake can quickly turn that access into a security incident. To red

breach

CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks

After attacks hit 30+ Minnesota water systems, CISA urged utilities to remove internet-exposed PLCs and strengthen OT security. Between Sunday and Monday, July 26 and 27, a coordinated cyberattack hit operational technology (OT) systems at more than 30 community water utilities across the state, according to Minnesota IT Services (MNIT). “A coordinated cyberattack targeted operational technology [

security

Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)

Introduction

vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG