Tuesday, December 3, 2024
HomeCyber CrimeAvosLocker and Cerber2021 Ransomware Exploit Confluence Bug

AvosLocker and Cerber2021 Ransomware Exploit Confluence Bug

AvosLocker and Cerber2021 Ransomware Exploit Confluence Bug

Ransomware organizations are exploiting an RCE vulnerability in Atlassian Confluence Server and Data Center instances that has already been fixed. The vulnerability is being actively abused for initial access to target networks, as it has already been exploited by several new botnets. The issue CVE-2022-26134 was exploited a week ago to install web shells and get remote code execution.

AvosLocker is taking advantage of the weakness.

Prodaft researchers observed that AvosLocker ransomware affiliates are widely exploiting the weakness (CVE-2022-26134) by attacking unpatched servers.

AvosLocker uses extensive network scans to hunt for exposed systems that are utilised to operate Atlassian Confluence installations.

Multiple organisations in the United States, Australia, and Europe have already been targeted by the operatives.

The Cerber malware exploited the weakness.

Cerber2021 ransomware has been reported by several victims, and it is aggressively targeting and encrypting Confluence systems that have not been patched for CVE-2022-26134.

The revelation of CVE-2022-26134 PoC vulnerabilities correlates with an uptick in successful Cerber ransomware assaults.

In addition, Microsoft has acknowledged that Confluence servers were hacked in order to deploy Cerber2021.

Conclusion

Cerber and AvosLocker, two ransomware gangs, have jumped on board to exploit the vulnerabilities in Confluence instances. This demonstrates how active cyber attackers are in exploiting zero-day vulnerabilities in widely used commercial goods. As a result, experts advise updating Confluence to remain safe from active abuse.

IEMA IEMLabs
IEMA IEMLabshttps://iemlabs.com
IEMLabs is an ISO 27001:2013 and ISO 9001:2015 certified company, we are also a proud member of EC Council, NASSCOM, Data Security Council of India (DSCI), Indian Chamber of Commerce (ICC), U.S. Chamber of Commerce, and Confederation of Indian Industry (CII). The company was established in 2016 with a vision in mind to provide Cyber Security to the digital world and make them Hack Proof. The question is why are we suddenly talking about Cyber Security and all this stuff? With the development of technology, more and more companies are shifting their business to Digital World which is resulting in the increase in Cyber Crimes.
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular

Recent Comments

Izzi Казино онлайн казино казино x мобильді нұсқасы on Instagram and Facebook Video Download Made Easy with ssyoutube.com
Temporada 2022-2023 on CamPhish
2017 Grammy Outfits on Meesho Supplier Panel: Register Now!
React JS Training in Bangalore on Best Online Learning Platforms in India
DigiSec Technologies | Digital Marketing agency in Melbourne on Buy your favourite Mobile on EMI
亚洲A∨精品无码一区二区观看 on Restaurant Scheduling 101 For Better Business Performance

Write For Us