logo

Hackers hijack OpenMetadata apps in Kubernetes cryptomining attacks

ID: df29f90c-927b-5ebb-ba2e-25f130f969e1

STIX ID: report--df29f90c-927b-5ebb-ba2e-25f130f969e1

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-04-17

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Attackers are actively exploiting five critical OpenMetadata vulnerabilities (CVE-2024-28255, CVE-2024-28847, CVE-2024-28253, CVE-2024-28848, CVE-2024-28254) in internet-exposed Kubernetes workloads to achieve remote code execution, deploy cryptomining malware, open reverse shells (via netcat), and persist using cronjobs. Microsoft observed these intrusions since early April; OpenMetadata released patches in version 1.2.4 on January 5 and administrators are advised to patch, avoid exposing default credentials, and inventory OpenMetadata images in clusters.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.