Hi Atlassian, I need to highlight some cybersecurity vulnerabilities with your products particularly Jira. I think some tightening and measures and Cybersecurity reporting points should be in place to prevent this sort of Atlassian product abuse.
Examaple culprint Jira site: https://e20ltu31.atlassian.net/ Im currently attached by the hacker to this Jira site)
Right under your noses Russian hackers are setting up these fake sites in Jira and then sending invites to emails that could be potential victims of viral infections or hack attacks.
The invite I reieved from this site: https://e20ltu31.atlassian.net/
And the verification request I recieved from Atlassian to login eventhough I dont have an account yet. What you need to do in those emqails is: 1) Have an option like facebook to report unauthorised invitations. This is spam in my view as the viewer of the email. 2) prevent the invitation of emails that dont have associated Atlasssian accounts.Makes seense to prevent it from being abused in this way:
Then I setup an account by resetting the password they created using my email and their own password. And went into Jira Service Management for site: https://e20ltu31.atlassian.net/
And other unsuspecting victims they invited in the Team list for this Jira site:
It was necessary to expose this on your community site as you havent got proper Cybersecurity tip hotline or reporting email address to send all this even if I dont have an account.
Please consider improving your cybersecurity practices or be used as a tool by hackers to attack Australian and other citizens who may be affected by these attacks.
Regards,
M