Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
No Result
View All Result

CloudSEK Employee’s Jira Account Breached, the Network Remains Secure

Altszn.com by Altszn.com
December 9, 2022
in Dark Web
0
CloudSEK Employee’s Jira Account Breached, the Network Remains Secure
399
SHARES
2.3k
VIEWS
Share on FacebookShare on Twitter


The image shows a Dell laptop on top of a white counter.
Cybercriminals acquired Jira credentials from a compromised laptop at CloudSEK. The network remains secure.
Source: Unsplash

Cybercriminals have acquired a CloudSEK employee’s Jira credentials and Confluence documents. They acquired this through malware installed on the employee’s laptop, confirmed CloudSEK in a blog released to update the public on the breach. According to company sources, the threat actor, sedut, has offered to sell the sensitive CloudSEK information on darknet forums. The compromised information includes XVigil, ProjectX, Codebase, Jira, email, and social media accounts. 

Sedut has no reputation on darknet forums, indicating they set up a new account to release CloudSEK’s data. In the CloudSEK blog, the company invalidated many of the cybercriminals’ claims of the breach’s extent. CloudSEK suspects it to be the work of a rival cybersecurity firm, as the attack does not indicate a typical cybercrime group. Back in October, CloudSEK documented a Jira software vulnerability that cybercriminals were actively exploiting in the wild. 

CloudSEK’s blog further informed the public that their team is investigating the data breach that occurred after “an employee’s Jira password was compromised…”. They also confirmed that “…the attacker has some internal details like screenshots, bug reports, names of customers, and schema diagrams.” 

Cybercriminals Breached Jira Application, but Couldn’t Do Much Damage 

The image shows a darknet forum selling access to CloudSEK's data. White text on black background.
Despite bold claims, the attacker has released no real data on CloudSEK.
Source: Bleeping Computer

The blog revealed that the security breach dates back to late November 2022. The breach occurred when CloudSEK approached a third-party provider (Axiom) to repair a laptop one of the employees was using. But the provider supposedly returned the laptop with a new Windows version and a stealer malware (Vidar). Later, in December, posts appeared on darknet forums selling the company’s stolen information. CloudSEK’s database was going for USD10,000, and the code for USD8,000. 

On further investigating the leak, CloudSEK determined that besides a few purchase orders and some customer information, most claims made by sedut are false — CloudSEK’s database and code are both secure. 

What CloudSEK is admitting, however, is that the cybercriminals accessed Jira tickets and internal Confluence pages. This is also evident from the screenshots on the darknet. The screenshots of Elastic DB, MySQL Schema, and xVigil, were taken from training documents stored on either Jira or Confluence. 

In terms of actual damage, the attackers only managed to compromise the names and purchase orders of three customers — a relatively minor cost compared to other data breaches affecting millions of users. CloudSEK confirms that no customer credentials and VPNs have been compromised, contrary to the attacker’s claims. 

MFA Saves the Day for CloudSEK 

The image shows a laptop keypad with a lock on top, surrounded by swirling colors.
Multi-factor authentication (MFA) is the gold standard in network security. MFA foiled the attackers’ plans.
Source: Unsplash

The stealer log malware uploaded the Jira passwords/cookies on the company laptop to a darknet marketplace. On the same day, the attacker purchased the logs but couldn’t access other passwords, because they were protected with multi-factor authentication (MFA). This added security step is the gold standard in network security, and for good reason. The attacker then had to resort to using session cookies to restore Jira sessions.

CloudSEK keeps no sensitive client information, which, alongside MFA, is a surefire way to avoid legal claims and uphold data integrity. Their company “doesn’t store critical information about their customers,” states the official blog release. “CloudSEK is a SaaS company whose products leverage public data to provide external threat intelligence in the form of initial access vectors and TTPs. No data from this breach can be used to launch supply chain attacks on customers.”

These robust cybersecurity measures helped save CloudSEK from major financial and reputational damages. In similar cases, cybercriminals waste no time infecting company laptops with all types of malware, spyware, Trojan horses, ransomware, etc., to unleash devastating attacks. 

Access to a company’s hardware allows cybercriminals to choose from an unlimited array of attack vectors. These attacks aren’t available to them when launching online breaches or social engineering scams. A company with compromised devices must scan for other infected endpoint devices and quarantine them to local networks. 

Project Management and Messaging Platforms Are a Risk for Companies

CloudSEK website documenting a Jira software vulnerability. Black text against a white background.
CloudSEK documented a prior Jira vulnerability in 2021.
Source: CloudSEK

Companies often use Jira — an agile management platform for software teams — in tandem with Confluence — a platform for managing written information. Atlassian owns both of these tools. Over 65,000 companies use Jira in integration with other software, and it captures about 36% of the project software management market. 

For many SMBs and corporate enterprises, project management platforms and communication tools are a serious vulnerability in their security apparatus. No matter how secure a network is, cybercriminals, with a little help from an unsuspecting employee, can bring it down like a house of cards with a single share over a messaging platform. 

Similarly, most project management tools aren’t as secure as encrypted applications. Cybercriminals can gain access to project management tools like Jira, Slack, Trello, Asana, ClickUp, Wrike, Monday, etc. once they have access they work up to socially engineer further information. 

Damage Could Have Been Far More Serious

While the cybercriminals did manage to gain access to Jira and Confluence documents, the damage’s extent was limited. In this instance, the fault doesn’t lie with either Jira, Confluence, or any project management tool or messaging application. 

The fault lies with the malicious third-party vendor that installed malware into the CloudSEK employee’s laptop. However, verifying ill intent is hard these days, especially since even established manufacturers like AMI MegaRPC have reported vulnerabilities in their BMC controllers. 

In retrospect, the damage could have been much, much worse. The MFA authentication saved the day for CloudSEK. And if the attack had been launched by an experienced cybercrime group with expertise in malware installation and network penetration, we would’ve had a different story to write. 



Read More: news.google.com

Tags: accountbreachedcloudsekdark webDarknetEmployeesJiraNetworkremainssecure
ADVERTISEMENT

Recent

Your AI ‘digital twin’ can take meetings and comfort your loved ones

Your AI ‘digital twin’ can take meetings and comfort your loved ones

May 11, 2025
Crypto AI tokens surge 34%, why ChatGPT is such a kiss-ass: AI Eye

Crypto AI tokens surge 34%, why ChatGPT is such a kiss-ass: AI Eye

May 10, 2025
El Salvador stacks 7 Bitcoin in last week, despite IMF deal

El Salvador stacks 7 Bitcoin in last week, despite IMF deal

May 10, 2025

Categories

  • Bitcoin (4,919)
  • Blockchain (11,558)
  • Crypto (9,499)
  • Dark Web (559)
  • DeFi (8,466)
  • Ethereum (4,987)
  • Metaverse (7,698)
  • Monero (296)
  • NFT (1,569)
  • Solana (5,083)
  • Web3 (20,920)
  • Zcash (507)

Category

Select Category

    Advertise

    Advertise your site, company or product to millions of web3, NFT and cryptocurrency enthusiasts. Learn more

    Useful Links

    Advertise
    DMCA
    Contact Us
    Privacy Policy
    Shipping & Returns
    Terms of Use

    Resources

    Exchanges
    Changelly
    Web3 Jobs

    Recent News

    Your AI ‘digital twin’ can take meetings and comfort your loved ones

    Your AI ‘digital twin’ can take meetings and comfort your loved ones

    May 11, 2025
    Crypto AI tokens surge 34%, why ChatGPT is such a kiss-ass: AI Eye

    Crypto AI tokens surge 34%, why ChatGPT is such a kiss-ass: AI Eye

    May 10, 2025

    © 2022 Altszn.com. All Rights Reserved.

    No Result
    View All Result
    • Home
      • Home – Layout 1
      • Home – Layout 2
      • Home – Layout 3

    © Altszn.com. All Rights Reserved.

    • bitcoinBitcoin (BTC) $ 103,493.00
    • ethereumEthereum (ETH) $ 2,472.78
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.36
    • bnbBNB (BNB) $ 655.75
    • solanaSolana (SOL) $ 172.91
    • usd-coinUSDC (USDC) $ 0.999975
    • dogecoinDogecoin (DOGE) $ 0.230309
    • cardanoCardano (ADA) $ 0.791413
    • tronTRON (TRX) $ 0.261074
    • staked-etherLido Staked Ether (STETH) $ 2,468.78
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 103,660.00
    • suiSui (SUI) $ 3.96
    • chainlinkChainlink (LINK) $ 16.45
    • wrapped-stethWrapped stETH (WSTETH) $ 2,983.10
    • avalanche-2Avalanche (AVAX) $ 24.50
    • stellarStellar (XLM) $ 0.303722
    • shiba-inuShiba Inu (SHIB) $ 0.000016
    • hedera-hashgraphHedera (HBAR) $ 0.205459
    • the-open-networkToncoin (TON) $ 3.35
    • bitcoin-cashBitcoin Cash (BCH) $ 410.13
    • hyperliquidHyperliquid (HYPE) $ 23.91
    • usdsUSDS (USDS) $ 0.999986
    • leo-tokenLEO Token (LEO) $ 8.29
    • litecoinLitecoin (LTC) $ 100.43
    • polkadotPolkadot (DOT) $ 5.00
    • wethWETH (WETH) $ 2,465.43
    • pi-networkPi Network (PI) $ 0.908244
    • moneroMonero (XMR) $ 319.37
    • wrapped-eethWrapped eETH (WEETH) $ 2,627.85
    • bitget-tokenBitget Token (BGB) $ 4.78
    • pepePepe (PEPE) $ 0.000013
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 103,392.00
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • whitebitWhiteBIT Coin (WBT) $ 30.08
    • uniswapUniswap (UNI) $ 7.05
    • bittensorBittensor (TAO) $ 446.59
    • nearNEAR Protocol (NEAR) $ 3.19
    • aptosAptos (APT) $ 5.86
    • daiDai (DAI) $ 0.999679
    • okbOKB (OKB) $ 55.68
    • aaveAave (AAVE) $ 217.77
    • ondo-financeOndo (ONDO) $ 1.03
    • susdssUSDS (SUSDS) $ 1.05
    • ethereum-classicEthereum Classic (ETC) $ 19.70
    • internet-computerInternet Computer (ICP) $ 5.56
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • crypto-com-chainCronos (CRO) $ 0.098837
    • tokenize-xchangeTokenize Xchange (TKX) $ 35.11
    • bitcoinBitcoin (BTC) $ 103,493.00
    • ethereumEthereum (ETH) $ 2,472.78
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.36
    • bnbBNB (BNB) $ 655.75
    • solanaSolana (SOL) $ 172.91
    • usd-coinUSDC (USDC) $ 0.999975
    • dogecoinDogecoin (DOGE) $ 0.230309
    • cardanoCardano (ADA) $ 0.791413
    • tronTRON (TRX) $ 0.261074
    • staked-etherLido Staked Ether (STETH) $ 2,468.78
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 103,660.00
    • suiSui (SUI) $ 3.96
    • chainlinkChainlink (LINK) $ 16.45
    • wrapped-stethWrapped stETH (WSTETH) $ 2,983.10
    • avalanche-2Avalanche (AVAX) $ 24.50
    • stellarStellar (XLM) $ 0.303722
    • shiba-inuShiba Inu (SHIB) $ 0.000016
    • hedera-hashgraphHedera (HBAR) $ 0.205459
    • the-open-networkToncoin (TON) $ 3.35
    • bitcoin-cashBitcoin Cash (BCH) $ 410.13
    • hyperliquidHyperliquid (HYPE) $ 23.91
    • usdsUSDS (USDS) $ 0.999986
    • leo-tokenLEO Token (LEO) $ 8.29
    • litecoinLitecoin (LTC) $ 100.43
    • polkadotPolkadot (DOT) $ 5.00
    • wethWETH (WETH) $ 2,465.43
    • pi-networkPi Network (PI) $ 0.908244
    • moneroMonero (XMR) $ 319.37
    • wrapped-eethWrapped eETH (WEETH) $ 2,627.85
    • bitget-tokenBitget Token (BGB) $ 4.78
    • pepePepe (PEPE) $ 0.000013
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 103,392.00
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • whitebitWhiteBIT Coin (WBT) $ 30.08
    • uniswapUniswap (UNI) $ 7.05
    • bittensorBittensor (TAO) $ 446.59
    • nearNEAR Protocol (NEAR) $ 3.19
    • aptosAptos (APT) $ 5.86
    • daiDai (DAI) $ 0.999679
    • okbOKB (OKB) $ 55.68
    • aaveAave (AAVE) $ 217.77
    • ondo-financeOndo (ONDO) $ 1.03
    • susdssUSDS (SUSDS) $ 1.05
    • ethereum-classicEthereum Classic (ETC) $ 19.70
    • internet-computerInternet Computer (ICP) $ 5.56
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • crypto-com-chainCronos (CRO) $ 0.098837
    • tokenize-xchangeTokenize Xchange (TKX) $ 35.11