Kong image compromise (Incident)
ID: 889549a0-06cb-5b2f-a138-caa0846c33ce
STIX ID: report--889549a0-06cb-5b2f-a138-caa0846c33ce
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-01-02
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
A compromised Kong Ingress Controller v3.4 container image was published to DockerHub and remained available for over a week; infected instances exhibited significant CPU usage (~4 cores) consistent with cryptojacking/resource hijacking. The report highlights script injection into the CI/CD workflow as the probable initial access vector and links to a GitHub security advisory and public posts discussing the incident.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
