Hackers Exploit OpenMetadata Flaws to Mine Crypto on Kubernetes
ID: 74f3670e-2854-5061-abc9-8f2e6cf733d9
STIX ID: report--74f3670e-2854-5061-abc9-8f2e6cf733d9
Feed Name: The Hacker News
Threat Score
Microsoft Threat Intelligence observed threat actors exploiting multiple high-severity OpenMetadata CVEs (SpEL injection and an auth bypass) to achieve unauthenticated RCE on internet-exposed workloads, conduct reconnaissance (including out-of-band checks to oast.me/Interactsh), deploy Windows/Linux crypto-miners, establish reverse shells, and maintain persistence via cron; users are advised to update images, avoid default credentials, and adopt strong authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
