Active Exploitation in the Wild: Critical Qinglong Bypasses Fuel Covert Cryptomining Campaign
ID: d32af561-6064-5ad9-9fdf-eecca45434db
STIX ID: report--d32af561-6064-5ad9-9fdf-eecca45434db
Feed Name: securityonline.info
Threat Score
Snyk warns of active exploitation of two authentication-bypass vulnerabilities in Qinglong (<=2.20.1) that allow unauthenticated RCE; attackers modify configs to deploy a cross-platform cryptocurrency miner disguised as ".fullgc" (indicators: /ql/data/db/.fullgc, config.sh references, domain "551911"); operators should patch middleware, remove infected Docker volumes, and rebuild containers with the patched image.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
