logo

Hackers Exploit OpenMetadata Flaws to Mine Crypto on Kubernetes

ID: 74f3670e-2854-5061-abc9-8f2e6cf733d9

STIX ID: report--74f3670e-2854-5061-abc9-8f2e6cf733d9

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-04-18

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Microsoft Threat Intelligence observed threat actors exploiting multiple high-severity OpenMetadata CVEs (SpEL injection and an auth bypass) to achieve unauthenticated RCE on internet-exposed workloads, conduct reconnaissance (including out-of-band checks to oast.me/Interactsh), deploy Windows/Linux crypto-miners, establish reverse shells, and maintain persistence via cron; users are advised to update images, avoid default credentials, and adopt strong authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.