Real-world Cyber Attacks Targeting Data Science Tools
ID: 73af2d96-fec4-52ef-bac1-1df315ae0c2c
STIX ID: report--73af2d96-fec4-52ef-bac1-1df315ae0c2c
Feed Name: Aqua Security Blog
This report details active, in-the-wild attacks against data science tooling—especially exposed Jupyter Notebook and JupyterLab instances—showing automated discovery via internet scanning, TeamTNT botnet campaigns that install cryptominers and backdoors, manual deployments of a Python-based ransomware, use of Cobalt Strike payloads, reverse shells, credential theft, and attempts to escalate privileges (including exploitation of Dirty Pipe). It includes captured IOCs, attack chains, and practical detection/mitigation guidance for protecting data platforms and limiting attacker impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
