logo

Exposed Training Open the Door for Crypto-Mining in Fortune 500 Cloud Environments

ID: da5e181d-14e1-51e7-b890-3c3cae54ba4f

STIX ID: report--da5e181d-14e1-51e7-b890-3c3cae54ba4f

Feed Name: The Hacker News

Date Published: 2026-02-11

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Pentera Labs found nearly 2,000 publicly exposed, intentionally vulnerable training/demo applications—about 60% on customer-managed AWS, Azure, or GCP—often connected to privileged cloud identities, creating paths for lateral movement beyond the host. Approximately 20% of instances contained evidence of active compromise (e.g., cryptomining, webshells, persistence), with exposures observed even in Fortune 500 environments and major cybersecurity vendors. The research underscores that mislabeled “training/test” systems, weak defaults, and excessive permissions turn these apps into real attack entry points and should be governed by the same security and lifecycle controls as production assets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.