logo

Attackers exploiting new critical OpenMetadata vulnerabilities on Kubernetes clusters

ID: 0d76e371-829e-5821-9c50-b16624aaa494

STIX ID: report--0d76e371-829e-5821-9c50-b16624aaa494

Feed Name: Microsoft Security

Threat Score
70/100

Date Published: 2024-04-17

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft observed attackers exploiting multiple critical OpenMetadata CVEs (affecting versions prior to 1.3.1) in internet‑exposed Kubernetes workloads to achieve remote code execution, perform reconnaissance (including OAST/Interactsh callbacks), harvest environment credentials, deploy cryptomining malware, establish reverse shells and persistence via cronjobs; the report includes file and IP IoCs, Defender for Cloud detection examples, and recommends updating OpenMetadata images to 1.3.1+, removing internet exposure or enforcing strong authentication, and using provided IoCs for hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.