<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Atlassian &#8211; DEVOQ Technology</title>
	<atom:link href="https://www.devoq.gr/tag/atlassian/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.devoq.gr</link>
	<description></description>
	<lastBuildDate>Sat, 21 Jun 2025 12:22:28 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://i0.wp.com/www.devoq.gr/wp-content/uploads/2018/07/cropped-logo_ico.png?fit=32%2C32&#038;ssl=1</url>
	<title>Atlassian &#8211; DEVOQ Technology</title>
	<link>https://www.devoq.gr</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">192885280</site>	<item>
		<title>Threat Advisory – August 25 &#8211; 31</title>
		<link>https://www.devoq.gr/2022/08/31/threat-advisory-august-25-31/</link>
					<comments>https://www.devoq.gr/2022/08/31/threat-advisory-august-25-31/#respond</comments>
		
		<dc:creator><![CDATA[DEVOQ Technology]]></dc:creator>
		<pubDate>Wed, 31 Aug 2022 12:14:57 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Atlassian]]></category>
		<category><![CDATA[Bitbucket]]></category>
		<category><![CDATA[command injection vulnerability]]></category>
		<guid isPermaLink="false">https://devoq.gr/?p=11114949</guid>

					<description><![CDATA[A critical command injection vulnerability in a Bitbucket product could allow an attacker to execute arbitrary code, researchers warn]]></description>
										<content:encoded><![CDATA[
<h1 style="text-align: center;"><span style="color: #333333;">CySec News</span></h1>
<p style="text-align: center;"><span style="color: #333333;">A critical <a style="color: #333333;" href="https://portswigger.net/web-security/os-command-injection">command injection</a> vulnerability in a Bitbucket product could allow an attacker to execute arbitrary code, researchers warn. Bitbucket is a Git-based source code repository hosting service owned by Atlassian. The flaw, tracked as CVE-2022-36804, is a command injection vulnerability in multiple API endpoints of <a style="color: #333333;" href="https://confluence.atlassian.com/bitbucketserver/bitbucket-server-and-data-center-advisory-2022-08-24-1155489835.html" target="_blank" rel="noopener">Bitbucket Server and Data Center</a>.</span></p>
<p style="text-align: center;"><span style="color: #333333;"><strong>Reference:</strong> https://portswigger.net/daily-swig/critical-command-injection-vulnerability-discovered-in-bitbucket-server-and-data-center</span></p>
<p style="text-align: center;"> </p>
<p style="text-align: center;"><span style="color: #333333;">Password management firm LastPass was hacked two weeks ago, enabling threat actors to steal the company&#8217;s source code and proprietary technical information.</span></p>
<p style="text-align: center;"><span style="color: #333333;"><strong>Reference:</strong> https://www.bleepingcomputer.com/news/security/lastpass-developer-systems-hacked-to-steal-source-code/</span></p>
<p style="text-align: center;"> </p>
<p style="text-align: center;"><span style="color: #333333;">Microsoft Azure customers&#8217; virtual machines (VMs) running Ubuntu 18.04 have been taken offline by an ongoing outage caused by a faulty systemd update. The outage started nine hours earlier, around 06:00 UTC, after the affected customers upgraded to systemd version 237-3ubuntu10.54 and their VMs started experiencing DNS errors, with no DNS resolver addresses available on impacted systems.</span></p>
<p style="text-align: center;"><span style="color: #333333;"><strong>Reference:</strong> https://www.bleepingcomputer.com/news/microsoft/microsoft-azure-outage-knocks-ubuntu-vms-offline-after-buggy-update/</span></p>
<p style="text-align: center;"> </p>
<p style="text-align: center;"><span style="color: #333333;">Five imposter extensions for the Google Chrome web browser masquerading as Netflix viewers and others have been found to track users&#8217; browsing activity and profit of retail affiliate programs. &#8220;The extensions offer various functions such as enabling users to watch Netflix shows together, website coupons, and taking screenshots of a website,&#8221; McAfee researchers Oliver Devane and Vallabh Chole <a style="color: #333333;" href="https://www.mcafee.com/blogs/other-blogs/mcafee-labs/malicious-cookie-stuffing-chrome-extensions-with-1-4-million-users/" target="_blank" rel="noopener">said</a>.</span></p>
<p style="text-align: center;"><span style="color: #333333;"><strong>Reference:</strong> https://thehackernews.com/2022/08/experts-find-malicious-cookie-stuffing.html</span></p>
<p style="text-align: center;"> </p>
<p style="text-align: center;"><span style="color: #333333;">Nation-state threat actors are <a style="color: #333333;" href="https://thehackernews.com/2021/05/top-11-security-flaws-russian-spy.html" target="_blank" rel="noopener">increasingly adopting</a> and <a style="color: #333333;" href="https://team-cymru.com/blog/2022/05/03/sliver-case-study-assessing-common-offensive-security-tools/" target="_blank" rel="noopener">integrating the Sliver</a> command-and-control (C2) framework in their intrusion campaigns as a replacement for Cobalt Strike. &#8220;Given Cobalt Strike&#8217;s popularity as an attack tool, defenses against it have also improved over time,&#8221; Microsoft security experts <a style="color: #333333;" href="https://www.microsoft.com/security/blog/2022/08/24/looking-for-the-sliver-lining-hunting-for-emerging-command-and-control-frameworks/" target="_blank" rel="noopener">said</a>. &#8220;Sliver thus presents an attractive alternative for actors looking for a lesser-known toolset with a low barrier for entry.&#8221;</span></p>
<p style="text-align: center;"><span style="color: #333333;"><strong>Reference:</strong> https://thehackernews.com/2022/08/cybercrime-groups-increasingly-adopting.html</span></p>
<h1 style="text-align: center;"><span style="color: #333333;">CVE’s of the Week</span></h1>
<h2 style="text-align: center;"><span style="color: #333333;">Cisco</span></h2>
<p style="text-align: center;"><span style="color: #333333;"><a style="color: #333333;" title="CVE-2022-20921 security vulnerability details" href="https://www.cvedetails.com/cve/CVE-2022-20921/">CVE-2022-20921</a></span></p>
<h2 style="text-align: center;"><span style="color: #333333;">Dell</span></h2>
<p style="text-align: center;"><span style="color: #333333;"><a style="color: #333333;" title="CVE-2022-33932 security vulnerability details" href="https://www.cvedetails.com/cve/CVE-2022-33932/">CVE-2022-33932</a></span></p>
<p style="text-align: center;"><span style="color: #333333;"><a style="color: #333333;" title="CVE-2022-32480 security vulnerability details" href="https://www.cvedetails.com/cve/CVE-2022-32480/">CVE-2022-32480</a></span></p>
<p style="text-align: center;"><span style="color: #333333;"><a style="color: #333333;" title="CVE-2022-31238 security vulnerability details" href="https://www.cvedetails.com/cve/CVE-2022-31238/">CVE-2022-31238</a></span></p>
<p style="text-align: center;"><span style="color: #333333;"><a style="color: #333333;" title="CVE-2022-31237 security vulnerability details" href="https://www.cvedetails.com/cve/CVE-2022-31237/">CVE-2022-31237</a></span></p>

]]></content:encoded>
					
					<wfw:commentRss>https://www.devoq.gr/2022/08/31/threat-advisory-august-25-31/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">11114949</post-id>	</item>
	</channel>
</rss>
