216.73.216.6

Attackers exploiting new critical vulnerabilities on Kubernetes clusters

· Published 21/05/2024 11:20 · Modified 21/05/2024 11:37

Export JSON

Essential information

Published
21/05/2024 11:20
Modified
21/05/2024 11:37
Tags
2024-05-21 cloud exploitation kubernetes openmetadata
Related entities
6 observables, 12 techniques (mitre)

Description

Microsoft security researchers have uncovered an attack campaign exploiting recently disclosed critical vulnerabilities in the platform to gain unauthorized access to clusters, followed by reconnaissance and the deployment of crypto-mining malware. The vulnerabilities, affecting versions before 1.3.1, allow attackers to bypass authentication and achieve remote code execution. Once gaining initial access, the attackers attempt to gather information about the compromised environment, establish command-and-control, and deploy malicious payloads for cryptocurrency mining. Administrators are advised to update to the latest patched version and utilize security solutions like Microsoft Defender for to detect and mitigate such threats.

External references