
2/1/2024 · Matthew Prince, John Graham-Cumming, Grant Bourzikas
What this post added
This post details a security incident where a threat actor gained access to Cloudflare's internal Atlassian servers using unrotated credentials from a previous Okta compromise. The incident involved reconnaissance, access to Jira, Confluence, and Bitbucket, and attempts to gain further access. Cloudflare's response involved a 'Code Red' remediation effort, including rotating over 5,000 production credentials, physically segmenting systems, reimaging and rebooting global network machines, and replacing hardware in a new data center. The post emphasizes the effectiveness of Cloudflare's Zero Trust architecture in limiting lateral movement and protecting customer data, while also highlighting lessons learned regarding internal credential management and system hardening.