Don't Just Read the News, Understand It.
Published loading...Updated

Illicit Crypto-Miners Pouncing on Insecure DevOps Tools

  • Security researchers at Wiz detected a campaign by attacker JINX-0132 exploiting exposed DevOps tools for illicit cryptocurrency mining in 2025.
  • The campaign exploits misconfigurations and vulnerabilities in HashiCorp Nomad, Consul, Gitea, and Docker APIs, often due to default or weak security settings.
  • JINX-0132 abuses public APIs to create multiple seemingly random services that download and run the open-source XMRig miner fetched directly from GitHub to avoid detection.
  • Wiz reports that 25% of cloud environments run these tools, 5% expose them publicly, and 30% of exposed deployments are misconfigured, putting up to a quarter of users at risk.
  • The campaign demonstrates that unsecured DevOps APIs allow remote code execution across connected nodes, highlighting the urgent need to patch, restrict access, and avoid exposing APIs publicly.
Insights by Ground AI
Does this summary seem wrong?

11 Articles

All
Left
Center
1
Right
Global Security Mag OnlineGlobal Security Mag Online
Reposted by
Global Security Mag OnlineGlobal Security Mag Online

Sysdig's Threat Research (TRT) team recently discovered that a group of cybercriminals were exploiting a configuration flaw on Open WebUI - a very popular open source web interface (95,000 stars on GitHub), allowing to interact and improve AI models such as LLM – in order to infiltrate a client's server and deploy crypto-mining software. How? By taking advantage of admin access left open and without authentication on the Internet by mistake, cyb…

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center
Factuality

To view factuality data please Upgrade to Premium

Ownership

To view ownership data please Upgrade to Vantage

The Hacker News broke the news in on Monday, June 2, 2025.
Sources are mostly out of (0)