Hackers Exploiting Jenkins Script Console for Cryptocurrency Mining Attacks
ID: f8e09a45-9f0d-515d-a09b-d959e6876433
STIX ID: report--f8e09a45-9f0d-515d-a09b-d959e6876433
Feed Name: The Hacker News
Threat Score
Trend Micro researchers discovered that misconfigured Jenkins Script Console endpoints exposed on the Internet can be abused to achieve remote code execution; attackers have used a Base64-encoded Groovy script to deploy a cryptocurrency miner (hosted on berrystore.me), establish persistence, and manage CPU usage. The report warns administrators to enforce authentication and authorization, audit instances, and avoid publicly exposing Jenkins to mitigate this active threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
