Hackers exploit RCE flaws in Qinglong task scheduler for cryptomining
ID: ea46d46f-53d1-5b88-95d7-4fff036f9b98
STIX ID: report--ea46d46f-53d1-5b88-95d7-4fff036f9b98
Feed Name: Bleeping Computer
Snyk researchers report that two authentication-bypass flaws in the Qinglong open-source task scheduler (affecting versions ≤2.20.1: CVE-2026-3965 and CVE-2026-4047) were chained to achieve remote code execution and actively exploited beginning February 7 to install cryptominers. Attackers modified Qinglong config.sh to download miner binaries (Linux x86_64, ARM64, macOS) to /ql/data/db/.fullgc and run them in the background; infections were confirmed across various setups (including behind Nginx/SSL). The maintainer issued a partial mitigation before a correct authentication-fix PR, and Snyk notes the root cause is a mismatch between middleware auth logic and Express.js routing behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
