Cyber Hacking News

Cloudflare hacked using stolen Okta auth tokens

0

Cloudflare disclosed that a nation state hacker has breached its internal Atlassian server, who gained access to its Confluence wiki, Jira bug database, and Bitbucket source code management system.

The threat actor first gained access to Cloudflare’s self-hosted Atlassian server on November 14 and then accessed the company’s Confluence and Jira systems following a reconnaissance stage.

They then came back on November 22 and established persistent access to the Atlassian server using ScriptRunner for Jira, gained access to the source code management system (which uses Atlassian Bitbucket), and tried, unsuccessfully, to access a console server that had access to the data center that Cloudflare had not yet put into production in São Paulo, Brazil.

To access its systems, the attackers used one access token and three service account credentials stolen during a previous compromise linked to Okta’s breach from October 2023 that Cloudflare failed to rotate.

Cloudflare detected the malicious activity on November 23, and they locked out the hacker on November 24, and its cybersecurity forensics specialists began investigating the incident on November 26.

To prevent the attacker from using the obtained technical information, Cloudflare’s staff rotated all production credentials (over 5,000 unique ones), physically segmented test and staging systems, performed forensic triage on 4,893 systems, reimaged and rebooted all systems on the company’s global network, including all Atlassian servers (Jira, Confluence, and Bitbucket) and machines accessed by the attacker.

All equipment in Cloudflare’s Brazil data center was later returned to the manufacturers to ensure that the data center was 100% secure.

Remediation efforts ended on January 5th, but the company says that its staff is still working on software hardening, as well as credential and vulnerability management.

The company says that this breach did not impact Cloudflare customer data or systems; its services, global network systems, or configuration were also unaffected.

According to the report, this was a security incident involving a sophisticated nation-state actor with the goal of obtaining persistent and widespread access to Cloudflare’s global network.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Data of 750 M Indian Mobile subscribers sold on hacker forums

Previous article

Interpol-Led initiative targets 1300 suspicious IPs

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *