Hackers possibly connected to the Chinese government since December have exploited two zero-days in a VPN from software developer Ivanti that is widely used by
Atlassian Confluence Data Center and Server instances infected with the Effluence backdoor through the exploitation of the critical vulnerability, tracked as CVE-2023-22515, remained compromised even after the application of issued patches, reports The Hacker News.
Government organisations are at risk after a mass hack attack delivered ransomware to the systems of multiple organisations using flawed Atlassian Confluence collaboration software, according to alerts raised by the firm and security vendor Rapid7.