Related Threat Clusters
-
Critical Zero-Day Vulnerabilities in Atlassian Confluence Exploited
Atlassian Confluence has faced multiple critical vulnerabilities, including CVE-2022-26134 and CVE-2023-22515. CVE-2022-26134, published on June 3, 2022, is an unauthenticated remote code execution vulnerability that…
3 articles · Updated June 17, 2026 -
Critical Vulnerability in syracom AG 2FA Plugin for Atlassian Products
The Secure Login (2FA) plugin for Atlassian Jira, Confluence, and Bitbucket has a serious broken access control vulnerability. This flaw allows attackers with valid user credentials to bypass multi-factor authentication…
3 articles · Updated June 17, 2026 -
RovoBlast Vulnerability Exposes Enterprise Data via One-Click Attack
Atlassian's Rovo AI assistant was found vulnerable to a one-click prompt injection attack, dubbed RovoBlast, which allows attackers to inject malicious instructions into authenticated user sessions. This vulnerability…
4 articles · Updated August 10, 2026 -
Claude Code MCP Traffic Hijacked to Steal OAuth Tokens
A new man-in-the-middle (MitM) attack has been identified, targeting Anthropic's Claude Code ecosystem. Threat actors exploit vulnerabilities in the Model Context Protocol (MCP) traffic to intercept OAuth authentication…
3 articles · Updated June 8, 2026 -
F5 BIG-IP Exploited in Multi-Stage Cyber Intrusion Attack
A multi-stage cyber intrusion attack exploited an exposed F5 BIG-IP edge appliance, leading to identity-focused attacks that accessed Active Directory and involved credential theft from an internal Confluence server.…
3 articles · Updated May 23, 2026 -
Critical RCE Vulnerability in BeyondTrust Software Requires Immediate Patching
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
1495 articles · Updated February 9, 2026 -
Drones Used in Cyberattack on Financial Firm: New Espionage Tactics Emerge
In a recent incident, modified drones were used to infiltrate the Wi-Fi network of a US East Coast financial firm. Security researcher Greg Linares reported that unusual activity on the firm's internal Atlassian…
7 articles · Updated May 10, 2026 -
Standard Bank Data Breach: Hackers Release Stolen Customer Data
On April 17, 2026, hackers publicly released data stolen from Standard Bank, following a breach disclosed on March 23, 2026. The breach involved unauthorized access to internal systems, exposing client records such as…
4 articles · Updated April 17, 2026 -
Adaptavist Group Breach: Ransomware Claims Major Data Theft
The Adaptavist Group, a UK enterprise software consultancy, is investigating a security breach that occurred in late March 2026, when an attacker gained unauthorized access using stolen credentials. CEO Simon…
4 articles · Updated April 21, 2026
Recent Intelligence Reports
- Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant — Infosecurity-Magazine · August 10, 2026
- One — Csoonline · August 10, 2026
- Atlassian Rovo Prompt Injection Exfiltrates Jira and Confluence Data Without User Approval — Cybersecuritynews · August 10, 2026
- 2026 05 11+ +Secure+Login+security+advisory+ +Broken+Access+Control — syracom-bee.atlassian.net · June 17, 2026
- Secure Login 2fa For Confluence — marketplace.atlassian.com · June 17, 2026
- Broken Access Control in syracom AG Secure Login (2FA) for Atlassian Jira / Confluence / Bitbucket — Sec-Consult · June 17, 2026
- Rapid7 Analysis: CVE-2023 — Rapid7 · June 17, 2026
- Mitiga Demonstrates Claude Code MCP Hijack Steals OAuth Tokens | Let's Data Science — Letsdatascience · June 8, 2026