惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

aimingoo的专栏
aimingoo的专栏
Engineering at Meta
Engineering at Meta
有赞技术团队
有赞技术团队
博客园_首页
Apple Machine Learning Research
Apple Machine Learning Research
Vercel News
Vercel News
G
Google Developers Blog
Blog — PlanetScale
Blog — PlanetScale
IT之家
IT之家
MongoDB | Blog
MongoDB | Blog
Y
Y Combinator Blog
B
Blog
The GitHub Blog
The GitHub Blog
M
MIT News - Artificial intelligence
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Stack Overflow Blog
Stack Overflow Blog
C
Check Point Blog
Microsoft Azure Blog
Microsoft Azure Blog
D
DataBreaches.Net
I
InfoQ
Recent Announcements
Recent Announcements
阮一峰的网络日志
阮一峰的网络日志
腾讯CDC
H
Help Net Security

New in Feedly

Automatically collect Splunk Hunting Queries that match your requirements | Feedly Continuously collect Suricata rules matching your requirements | Feedly Enrich and triage Apple security releases in the Vulnerability Intel Agent | Feedly Feedly completes SOC 2 Type 2 examination | Feedly VirusTotal Integration: Triage IOCs Faster in Feedly | Feedly Connect Feedly to OpenCTI: Real-Time Threat Intel, Automated | Feedly Feedly Best Practices for CTI Teams | Feedly GreyNoise + Feedly Threat Intelligence: Enriching IoCs | Feedly 7 AI Prompts for Cyberattack Pattern Analysis | Feedly Navigate Feedly Faster with Go To | Feedly Navigate Feedly Faster with Go To Introducing Feedly ThreatBeats: Your daily intel jingles | Feedly Introducing Feedly ThreatBeats: Your daily intel jingles 6 Ways to Automate Threat Intelligence with the Feedly API | Feedly Get threat intelligence to your team fast, in the tools they already use | Feedly Tracking the cyber consequences of geopolitical events | Feedly Analyze your closed-source intelligence in Feedly | Feedly Cyberattack Insights Cards: A dynamic 360° attack view | Feedly Cyberattack Insights Cards: A dynamic 360° attack view 7 ways to prioritize CVEs by how they're exploited | Feedly Ask AI on Threat Actor Insights Cards: Accelerate adversary research with custom queries | Feedly Research IoCs with rich context in seconds, not hours | Feedly Surface top threats in CTI newsletters | Feedly The Scanner: Exploring Potential Futures | Feedly The Radar: Detecting emerging signals | Feedly Prompt Engineering: Newsletter template for real-time phishing trends | Feedly The Monitor: Tracking the known present | Feedly Startup Innovation Radar: A real-time startup database | Feedly The InsightOS architecture | Feedly Feedly MCP Server: Automate CTI workflows with Claude and the Feedly Threat Graph | Feedly
Enrich and triage Atlassian security releases in the Vuln...
Andrew Castro · 2026-08-07 · via New in Feedly

Bottom-line-up-front (BLUF)

The Vulnerability Intel Agent now ingests each Atlassian security release within minutes of publication and continuously enriches every CVE with CVSS, EPSS, attack-path details, patch availability, and exploitation signals like proof-of-concept activity and CISA KEV as they emerge.

You can filter the release by attack path, the products you run, or your patch criteria to focus on the CVEs that require action.

Challenge

The number of CVEs disclosed in security releases is rising as vendors and researchers increasingly use AI to uncover vulnerabilities, while the time between disclosure and exploitation continues to shrink.

For a team running just a handful of Atlassian products, quickly identifying which CVEs actually matter from a recent security release, and then manually validating each against severity, attack path, and internal patching policies, becomes increasingly difficult as the list grows.

How does it work?

  • Add the filter. In the Vulnerability Intel Agent, select the Atlassian security release you want, or "Latest Atlassian Security Release," which always points at the most recent one, and set the date range. Every CVE from the release appears in the output table. Atlassian is one of several vendor advisories available.
  • Columns. Each enrichment field is a column, alongside the CVE ID and a plain description of the vulnerability. Reorder, show, or hide them to match how you triage.
  • Alerts. Deploy the Intel Agent and get notified when new CVEs match your filters.

Filter to your stack

Filter the release at the product level, down to the Atlassian products you actually run.

The July 21st release includes 3 CVEs affecting Confluence Data Center, Sourcetree, and Jira. You can focus on the systems in your environment and prioritize your patch or remediation accordingly.

Feedly's Vulnerability Intel Agent filtering through the products in the latest Atlassian security release that apply to their tech stack.

Filter by attack path

Add filters for attack vector, privileges required, and user interaction.

The July 21st, 2026 release includes 28 CVEs that can be reached by an attacker without credentials or any user interaction.

Feedly's Vulnerability Intel Agent filtering through the attack path of the CVEs in the latest Atlassian security release.

Filter by your patch policy

Most patch-now policies come down to a threshold: CVSS above a certain score, EPSS above a certain probability, or both. Set those thresholds as filters.

The July 21st release includes 17 CVEs at CVSS 8 and above with EPSS above 80%. You can remediate them immediately under your SLA and leave the rest for the normal patch cycle.

Feedly's Vulnerability Intel Agent filtering through high severity CVEs from the latest Atlassian security release.

Filter CVEs by attack path, products, or patch policy

Curious to see how Feedly Threat Intelligence can help you collect and prioritize Apple vulnerabilities faster?

Start Free Trial

FAQs

Does the Feedly Vulnerability Intel Agent support vendors other than Atlassian?

Yes. Atlassian is one of several vendor advisories available in the Vulnerability Intel Agent. We have: Adobe, Android, Apache, Apple, Microsoft, and Oracle.

Do I need to patch Atlassian Cloud products for new CVEs?

No. Atlassian handles patching for its Cloud products, so there's nothing on your side.

Are Atlassian Data Center products my responsibility to patch?

Yes. Data Center products are self-hosted, so patching and upgrades are on you. For some CVEs, remediation means upgrading to a newer version rather than patching the one you're on, which takes more planning.

Why do Atlassian security advisories list non-Atlassian software?

Atlassian advisories can include CVEs tied to the third-party components they embed, not just Atlassian products. Those are easy to miss in a regular CVE AI Feed, but you'll catch them working from the advisory.

How fast does Feedly ingest a new Atlassian security release?

Within minutes of publication. Each CVE is then enriched continuously as new signals emerge.

What is the "Latest Atlassian Security Release" filter in Feedly?

A filter that always points at the most recent Atlassian release, so you don't have to update it each time a new one drops.

How do I filter Atlassian CVEs by CVSS, EPSS, and attack path?

Set thresholds and filters on CVSS, EPSS, attack path (attack vector, privileges required, user interaction), patch availability, and exploitation signals like proof-of-concept activity and CISA KEV.

Can I get alerts for new Atlassian CVEs that match my filters?

Yes. Deploy the Intel Agent and get notified when new CVEs match your filters.