@sparsh.kulshrestha @Dan Hranj I think we are missing the big picture here.
If what Cloudsek is claiming is true, then it means that cookies were stolen via malware infections on endpoint computers.
What we do not have is a list of those that we can check and verify.
If Cloudsek has this list from darknet then it should notify Atlassian and let Atlassian contact affected customers to investigate their enpoints for breaches.
This would be the responsible thing to do.
Otherwise changing login settings and session timeouts is just a bandaid for a malware infection and continuous data breach.
We need to establish if the claims are true and notify parties of breaches if confirmed.
@atlassian should verify with Cloudsek the claims and respond accordingly.
In the article there is a link to a tool that can check if your domain is affected but it does not report on details.
We need these details to be available to investigate in our companies potential malware infections.
Cloudsek website unfortunately does not even have a contact page to send them an email.
Security Flaw in Atlassian Products (Jira, Confluence,Trello, BitBucket) Affecting Multiple Companies - CloudSEK