Looney Tunables Vulnerability Exploited by Kinsing
ID: 6456f666-2769-530b-8b6e-a741c727ad22
STIX ID: report--6456f666-2769-530b-8b6e-a741c727ad22
Feed Name: Aqua Security Blog
Aqua Nautilus researchers intercepted an active Kinsing campaign targeting cloud-native environments where attackers exploited a PHPUnit vulnerability (CVE-2017-9841) to deploy a reverse shell, manually tested and executed a Looney Tunables local privilege escalation exploit (CVE-2023-4911) to attempt root access, deployed obfuscated PHP/JS backdoors and attempted to harvest AWS instance metadata and temporary credentials; the report provides observed IOCs, MITRE ATT&CK mappings, detection guidance, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
