Hello! I have Confluence on my server ver. 6.8.
It was hacked somehow and somebody uses it to spam and flood from my server.
How is it possible? I have only atlassian (+nginx) and postgres on the server.
The malware is running as "confluence" user. They changed the crontab and run scripts from pastebin.com.
