Oct. 11, 2023, 4:12 a.m. | info@thehackernews.com (The Hacker News)

The Hacker News thehackernews.com

Microsoft has linked the exploitation of a recently disclosed critical flaw in Atlassian Confluence Data Center and Server to a nation-state actor it tracks as Storm-0062 (aka DarkShadow or Oro0lxy).
The tech giant's threat intelligence team said it observed in-the-wild abuse of the vulnerability since September 14, 2023.
"CVE-2023-22515 is a critical privilege escalation vulnerability in

abuse actor atlassian atlassian confluence center confluence confluence data center confluence vulnerability critical critical flaw cve cve-2023-22515 data data center exploitation exploiting flaw giant hackers intelligence microsoft nation nation-state actor nation-state hackers september server state storm storm-0062 team tech threat threat intelligence vulnerability

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)