In recent developments, a security breach has targeted Atlassian’s Confluence software, exploiting a zero-day vulnerability, known as CVE-2023-22515. Atlassian disclosed this vulnerability, acknowledging that a small number of its customers fell victim to these exploitations.
Microsoft has played a significant role in these recent findings, as they identified attack traffic associated with a threat actor named Storm-0062. This attack activity commenced on September 14 and has been linked to the IP addresses: 192.69.90.31, 104.128.89.92, 23.105.208.154, and 199.193.127.231.
The Significance targeting Atlassian’s Confluence software
Notably, the attack leverages CVE-2023-22515, allowing any device with a network connection to a vulnerable application to create a Confluence administrator account within the application. Microsoft further notes that “Storm-0062” goes by other aliases like DarkShadow or Oro0lxy.
While China is not explicitly mentioned, it’s worth highlighting that Oro0lxy is an alias connected to Li Xiaoyu. In a June 2020 indictment, the US Department of Justice (DoJ) accused Li Xiaoyu of engaging in hacking activities on behalf of China’s Ministry of State Security. These activities encompassed hacking numerous companies in multiple countries over a ten-year span.
This situation carries significant implications for cybersecurity and underscores the importance of robust security measures. The response from Atlassian and the ongoing investigation will reveal more details about the extent of the breach and its potential impact on affected parties.


