336K Prometheus Instances Exposed to DoS, 'Repojacking'
ID: b55e1553-5173-5e7b-8633-965241640df8
STIX ID: report--b55e1553-5173-5e7b-8633-965241640df8
Feed Name: Dark Reading
Researchers using Shodan discovered more than 40,000 exposed Prometheus servers and over 296,000 exposed exporters that leak plaintext credentials, tokens, and internal API addresses; the exposures also enable denial-of-service attacks (via the /debug/pprof endpoint) and repojacking-based remote code execution in some exporters. The report highlights scale, examples (including an exposed Prometheus instance for a major automaker), mitigation recommendations (remove public exposure, add authentication, monitor repo references), and that Prometheus maintainers have addressed some repojacking issues.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
