logo

Active Exploitation in the Wild: Critical Qinglong Bypasses Fuel Covert Cryptomining Campaign

ID: d32af561-6064-5ad9-9fdf-eecca45434db

STIX ID: report--d32af561-6064-5ad9-9fdf-eecca45434db

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Ddos

...
...

Snyk warns of active exploitation of two authentication-bypass vulnerabilities in Qinglong (<=2.20.1) that allow unauthenticated RCE; attackers modify configs to deploy a cross-platform cryptocurrency miner disguised as ".fullgc" (indicators: /ql/data/db/.fullgc, config.sh references, domain "551911"); operators should patch middleware, remove infected Docker volumes, and rebuild containers with the patched image.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.