Misconfigured Docker APIs are the new target of a malware campaign that transforms them into a cryptocurrency mining botnet for Dero currency using worm-like capabilities. Kaspersky has reported an unknown actor exploiting a Docker API, creating an illicit botnet. The malware propagation involves two components, nginx and the Dero miner “cloud”, each using a specific Docker API port. The campaign aims to mine the Dero cryptocurrency miner from GitHub and targets containerized infrastructures with insecurely published Docker API to the internet.

Integrating Threat Intelligence into Security Operations Centers
As cyber threats escalate, Security Operations Centers (SOCs) leverage threat intelligence to shift from reactive to proactive defenses. Integrating Cyber Threat Intelligence (CTI) enhances incident