logo

Crooks exploit OpenMetadata holes to mine crypto – and leave a sob story for victims

ID: 0d62e49a-4b93-5b36-b745-afbdede46a53

STIX ID: report--0d62e49a-4b93-5b36-b745-afbdede46a53

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-04-18

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Microsoft reports that threat actors are actively exploiting multiple high- and critical-severity OpenMetadata vulnerabilities (versions prior to 1.3.1) on internet-exposed Kubernetes clusters to bypass authentication and achieve remote code execution. Compromised containers are used to harvest environment credentials, deploy crypto-mining malware from a remote server, and maintain access via Netcat reverse shells and cronjob persistence; organizations should update OpenMetadata, avoid default credentials, and limit internet exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.