Close Menu
Finance Pro
  • Home
  • Art Gallery
  • Art Investment
  • Art Stocks
  • Cryptocurrency
  • Finance
  • Investing in Art
  • Investments
Facebook X (Twitter) Instagram
Trending
  • During Infrastructure Week, Governor Newsom announces $540 million investment to improve infrastructure statewide, connecting Californians to reliable and safe transportation – California State Portal | CA.gov
  • Mexico Data Center Market Investment & Growth Report 2026-2031 Featuring Key DC Investors – AWS, Ascenty, Equinix, Google, HostDime, KIO, Mexico Telecom Partners, Microsoft, ODATA, Scala – Yahoo Finance UK
  • EU Opens Public Consultation to Review MiCA Cryptocurrency Regulations
  • What actually is ‘reasonable financial provision’ for the purposes of the Inheritance (Provision for Family and Dependants) Act 1975? McDaniel v Talbot & Anor [2026] EWHC 928 (Ch) – Today's Wills and Probate
  • Regulator tells property lender Kingscrown Finance to stop taking on new customers
  • South Asian show at carwright Hall draws new Bradford audiences
  • Walthamstow Art Trail to return in June for 20th anniversary
  • Finance minister highlights AI capacity building for developing nations at G7
  • Privacy Policy
  • Terms and Conditions
  • Get In Touch
Finance ProFinance Pro
  • Home
  • Art Gallery
  • Art Investment
  • Art Stocks
  • Cryptocurrency
  • Finance
  • Investing in Art
  • Investments
Finance Pro
Home»Cryptocurrency»Crooks exploit OpenMetadata holes to mine crypto – and leave a sob story for victims • The Register
Cryptocurrency

Crooks exploit OpenMetadata holes to mine crypto – and leave a sob story for victims • The Register

April 18, 20244 Mins Read

[ad_1]

Crooks are exploiting month-old OpenMetadata vulnerabilities in Kubernetes environments to mine cryptocurrency using victims’ resources, according to Microsoft.

OpenMetadata is a suite of open-source software for organizing and working on non-trivial amounts of information, making it possible to search, secure, and export and import data, among other things.

In March, the project’s maintainers disclosed and fixed five security vulnerabilities that affected versions prior to 1.3.1, which could be abused to bypass authentication and gain remote code execution (RCE) within OpenMetadata deployments. 

Digital thieves have been exploiting the bugs in unpatched installations that are exposed to the internet since the beginning of April, according to a threat intelligence team at Microsoft, which itself is no stranger to horrific security bugs.

Those OpenMetadata vulnerabilities are:

  • CVE-2024-28255, a critical improper authentication flaw that received a 9.8-out-of-10 CVSS severity rating. It can allow an attacker to bypass the authentication mechanism and reach any arbitrary endpoint.
  • CVE-2024-28847, an 8.8-rated high-severity code-injection bug that can lead to RCE.
  • CVE-2024-28253, a code-injection flaw that can allow RCE. This one is rated critical, and has a 9.4 CVSS score.
  • CVE-2024-28848, another 8.8-rated code-injection flaw that can allow RCE.
  • CVE-2024-28254, an OS command injection flaw that received an 8.8 CVSS rating and can open users up to remote code execution.

To gain access, the attackers scan for Kubernetes-based deployments of OpenMetadata that are exposed to the internet. After finding vulnerable systems, they exploit the unpatched CVEs to gain access to the container, and then run a series of commands to collect information on the network and hardware configuration, OS version, and active users, among other information about the victim’s environment.

Election disinfo off to a slow start

In other Microsoft news, Redmond says Russia and China are stepping up efforts to stick their oars into the upcoming US presidential election, again.

Russian trolls “kicked into gear” in the past 45 days, with a “renewed focus on undermining US support for Ukraine,” according to the second Microsoft Threat Intelligence Election Report. This includes influence campaigns from at least 70 Russian-affiliated groups.

“The most prolific of these actors are backed by or affiliated with the Russian Presidential Administration, highlighting the increasingly centralized nature of Russian influence campaigns, rather than relying principally on its intelligence services and the Internet Research Agency (known more commonly as the troll farm) as seen during the 2016 US presidential election,” the report stated. 

It adds that these disinformation campaigns target both English and Spanish-speaking audiences in America and push anti-Ukraine narratives.

China, meanwhile, “uses a multi-tiered strategy that aims to destabilize targeted countries by exploiting increasing polarization among the public and undermining faith in centuries-old democratic systems,” we’re told. 

Plus, Beijing is much better than Russia at using generative AI to create convincing images and videos, Redmond says, noting that Storm-1376 (aka Spamouflage), remains one of the most prolific groups using AI to generate fake news. Our advice? Apply some common sense to things you see online, and stick to reputable, trusted sources of information.

“As part of the reconnaissance phase, the attackers read the environment variables of the workload,” Microsoft security boffins Hagai Ran Kestenberg and Yossi Weizman wrote.

In this case, “those variables may contain connection strings and credentials for various services used for OpenMetadata operation which could lead to lateral movement to additional resources.”

The attackers then download crypto-mining malware from a remote server in China, and, in some cases, add a personal note to the victim:

There’s no word from Redmond as to whether this sob story ever works, or ends with the victims happily transferring Monero crypto-coins (XMR) to the crooks. 

We do know, however, that after running the mining malware, the miscreants start a reverse shell connection using Netcat to maintain remote access to the container, and also install cronjobs for scheduling, which allows them to execute the malware at predetermined times.

“Administrators who run OpenMetadata workload in their cluster need to make sure that the image is up to date,” the Redmond duo wrote. “If OpenMetadata should be exposed to the internet, make sure you use strong authentication and avoid using the default credentials.” ®

[ad_2]

Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

EU Opens Public Consultation to Review MiCA Cryptocurrency Regulations

May 20, 2026 Cryptocurrency

Bitcoin slumps to a two-week low as Iran war builds pressure on cryptocurrency

May 17, 2026 Cryptocurrency

Investors Flocking to Super-Anonymous Cryptocurrency Used for the Sketchiest Stuff Imaginable

May 17, 2026 Cryptocurrency

#CryptoCornerSeason2 | Crypto Corner powered by Binance Kea Credit's Jo DSilva To @CNBCTV18News – Real World Asset Tokenisation has hit $370 bn as of April 2026 – BCG is estimating assets worth $60-64 tn to come on chain by end of 2030 Manisha – LinkedIn

May 15, 2026 Cryptocurrency

Australia’s Capital Gains Tax Overhaul Set to Impact Cryptocurrency Investors

May 14, 2026 Cryptocurrency

T3 Financial Crime Unit Seizes Over $450M in Criminal Cryptocurrency Operations

May 14, 2026 Cryptocurrency
Add A Comment
Leave A Reply Cancel Reply

Don't Miss

During Infrastructure Week, Governor Newsom announces $540 million investment to improve infrastructure statewide, connecting Californians to reliable and safe transportation – California State Portal | CA.gov

May 20, 2026 Investments 1 Min Read

[ad_1] During Infrastructure Week, Governor Newsom announces $540 million investment to improve infrastructure statewide, connecting…

Mexico Data Center Market Investment & Growth Report 2026-2031 Featuring Key DC Investors – AWS, Ascenty, Equinix, Google, HostDime, KIO, Mexico Telecom Partners, Microsoft, ODATA, Scala – Yahoo Finance UK

May 20, 2026

EU Opens Public Consultation to Review MiCA Cryptocurrency Regulations

May 20, 2026

What actually is ‘reasonable financial provision’ for the purposes of the Inheritance (Provision for Family and Dependants) Act 1975? McDaniel v Talbot & Anor [2026] EWHC 928 (Ch) – Today's Wills and Probate

May 20, 2026
Our Picks

During Infrastructure Week, Governor Newsom announces $540 million investment to improve infrastructure statewide, connecting Californians to reliable and safe transportation – California State Portal | CA.gov

May 20, 2026

Mexico Data Center Market Investment & Growth Report 2026-2031 Featuring Key DC Investors – AWS, Ascenty, Equinix, Google, HostDime, KIO, Mexico Telecom Partners, Microsoft, ODATA, Scala – Yahoo Finance UK

May 20, 2026

EU Opens Public Consultation to Review MiCA Cryptocurrency Regulations

May 20, 2026

What actually is ‘reasonable financial provision’ for the purposes of the Inheritance (Provision for Family and Dependants) Act 1975? McDaniel v Talbot & Anor [2026] EWHC 928 (Ch) – Today's Wills and Probate

May 20, 2026
Our Picks

UK finance ministry presses supermarkets to cap food prices, sources say

May 19, 2026

Welsh painter and art teacher has enjoyed a successful 14 months in Shetland, before recently receiving the dream offer of opening her own gallery in Fife

May 19, 2026

ChatGPT Can Now Access Your Bank Account — As OpenAI Expands Into Personal Finance

May 19, 2026
Latest updates

During Infrastructure Week, Governor Newsom announces $540 million investment to improve infrastructure statewide, connecting Californians to reliable and safe transportation – California State Portal | CA.gov

May 20, 2026

Mexico Data Center Market Investment & Growth Report 2026-2031 Featuring Key DC Investors – AWS, Ascenty, Equinix, Google, HostDime, KIO, Mexico Telecom Partners, Microsoft, ODATA, Scala – Yahoo Finance UK

May 20, 2026

EU Opens Public Consultation to Review MiCA Cryptocurrency Regulations

May 20, 2026
Weekly Updates

Next Cryptocurrency to Explode, 25 January — Toshi, GateToken, Vine Coin, XPR Network

January 25, 2025

𝗙𝗹𝗼𝘄 𝗦𝘁𝗮𝘁𝗲: ‘𝗣𝗼𝗲𝘁𝗿𝘆 𝗶𝗻 𝗠𝗼𝘁𝗶𝗼𝗻’ 𝗮𝘁 𝗧𝗵𝗿𝗶𝘃𝗲 𝗔𝗿𝘁 𝗚𝗮𝗹𝗹𝗲𝗿𝘆 It was a curious event to start the New Year: the usual viewing space at Thrive Art Gallery was cleared of its exhibition panels, the paintings and installations removed to the corners of th – facebook.com

January 7, 2026

“They’re Still Sitting on the Same Old Rails”: Ripple’s Jazzi Cooper

June 13, 2024
  • Privacy Policy
  • Terms and Conditions
  • Get In Touch
© 2026 Finance Pro

Type above and press Enter to search. Press Esc to cancel.