Attackers exploiting new critical OpenMetadata vulnerabilities on Kubernetes clusters
ID: 0d76e371-829e-5821-9c50-b16624aaa494
STIX ID: report--0d76e371-829e-5821-9c50-b16624aaa494
Feed Name: Microsoft Security
Microsoft observed attackers exploiting multiple critical OpenMetadata CVEs (affecting versions prior to 1.3.1) in internet‑exposed Kubernetes workloads to achieve remote code execution, perform reconnaissance (including OAST/Interactsh callbacks), harvest environment credentials, deploy cryptomining malware, establish reverse shells and persistence via cronjobs; the report includes file and IP IoCs, Defender for Cloud detection examples, and recommends updating OpenMetadata images to 1.3.1+, removing internet exposure or enforcing strong authentication, and using provided IoCs for hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
