Related Threat Clusters
-
Critical Vulnerability in syracom AG 2FA Plugin for Atlassian Products
The Secure Login (2FA) plugin for Atlassian Jira, Confluence, and Bitbucket has a serious broken access control vulnerability. This flaw allows attackers with valid user credentials to bypass multi-factor authentication…
3 articles · Updated June 17, 2026 -
Critical Vulnerabilities Discovered in Apache OFBiz Affecting All Versions Pre-24.09.06
Apache OFBiz has critical vulnerabilities that allow attackers to exploit hardcoded keys and bypass authentication. The vulnerabilities, CVE-2026-31986 and CVE-2026-45434, were published on 2026-05-19 and affect all…
3 articles · Updated May 21, 2026 -
GitHub and Jira Notification Systems Exploited for Phishing Attacks
Cybercriminals have exploited GitHub and Atlassian Jira's notification systems to send phishing emails that appear legitimate. These emails bypass standard security checks such as SPF, DKIM, and DMARC because they…
2 articles · Updated April 14, 2026 -
Spam Campaign Exploits Atlassian Cloud to Target Users with Fraudulent Schemes
Cybercriminals are utilizing Atlassian Cloud, specifically Jira, to conduct spam campaigns that redirect users to fraudulent investment schemes. By exploiting the trusted nature of the platform, attackers are bypassing…
3 articles · Updated February 18, 2026
Recent Intelligence Reports
- Mobile+app+login+does+not+work+with+Secure+Login — syracom-bee.atlassian.net · June 17, 2026
- Researchers at Aretiq AI discovered — aretiq.ai · May 21, 2026
- GitHub, Jira notification systems weaponized for phishing | brief — Scworld · April 14, 2026
- Scammers exploit trust in Atlassian Jira to target organizations — Feeds2.Feedburner · February 18, 2026