cognitive cybersecurity intelligence

News and Analysis

Search

Cryptojacking Campaign Exploits DevOps APIs Using Off-the-Shelf Tools from GitHub

Cryptojacking Campaign Exploits DevOps APIs Using Off-the-Shelf Tools from GitHub

Cybersecurity researchers have found a new cryptojacking campaign, known as JINX-0132, targeting public DevOps servers to illicitly mine cryptocurrencies. The attackers exploit vulnerabilities and misconfigurations in Docker, Gitea, and HashiCorp Consul and Nomad. Notably, the campaign marks the first known exploitation of Nomad misconfigurations. The use of GitHub repositories for downloading tools make attribution difficult. The hackers have compromised numerous servers, costing tens of thousands of dollars monthly.

Source: thehackernews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts