Breaking
June 6, 2025

Public DevOps tools targeted by criminals to steal crypto | usagoldmines.com


  • Security researchers Wiz find four major DevOps tools being abused
  • The misconfigurations allow threat actors to deploy cryptocurrency miners
  • A quarter of all instances are at risk, so users should be on their guard

Cybercriminals have been spotted abusing misconfigurations in popular public DevOps tools to deploy cryptocurrency miners – generating valuable tokens, while raking up huge electricity and computing bills for their victims.

Security researchers from Wiz Threat Research spotted the campaign and attributed it to a threat actor named JINX-0132.

Apparently, the crooks target many DevOps tools, but four stood out: Nomad, Consul, Docker Engine API, and Gitea.

Mitigation measures

The first two are built by HashiCorp: Nomad is a workload orchestrator that schedules and manages the deployment of containers, virtual machines, and standalone applications across clusters, while Consul is a service networking solution that provides service discovery, health checking, configuration, and segmentation for distributed applications.

Docker Engine API is a RESTful API that allows developers and automation tools to interact with the Docker daemon to manage containers, images, networks, and volumes, and Gitea is a self-hosted Git service that provides source code hosting, issue tracking, code review, and collaborative development tools through a web interface.

“Misconfiguration abuse by threat actors can often go under defenders’ radar, especially if the affected application isn’t well known as an attack vector,” the researchers explained.

“A key characteristic of JINX-0132’s methodology is the seemingly deliberate avoidance of any unique, traditional identifiers that could be used by defenders as Indicators of Compromise. Instead of utilizing attacker-controlled servers for payload delivery, they download tools directly from public GitHub repositories.”

The problem seems to be quite widespread, too, as up to a quarter of all cloud users could be exposed. In the report, the researchers said that 25% of all cloud environments are running at least one of the four technologies listed above. What’s more, at least 20% are running HashiCorp Consul.

“Of those environments using these DevOps tools, five percent expose them directly to the Internet, and among those exposed deployments, 30 percent are misconfigured,” the team concluded.

To mitigate the risks, companies should implement strict access controls, conduct regular security audits, and perform frequent vulnerability assessments. Furthermore, they should not stall on applying patches, and should monitor their systems for abnormal resource usage.

Finally, they should secure DevOps environments against misconfigurations, restrict unauthorized command execution, and strengthen their authentication measures.

Via The Register

You might also like

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

The iPhone 17 Air could lack a near-essential feature, but I'm not convinced | usagoldmines.com

The iPhone 17 is tipped to come with a MagSafe charging boost – but it might cost you | usagoldmine...

Running Windows on your Mac doesn’t have to suck — this app makes it easy | usagoldmines.com

Get the most out of your Nintendo Switch 2 with these 3 TVs I've picked to pair with it, including o...

Why most companies shouldn’t build their own AI solutions | usagoldmines.com

WordCamp Europe 2025 - all the latest news and updates as they happen | usagoldmines.com

The best monitors: 11 top picks for gaming, 4K, HDR, and more | usagoldmines.com

Luma Labs' new Modify Video tool can reimagine scenes without reshooting erichs211@gmail.com (Eric H...

Hard drive, SSD, or USB flash drive: Which portable storage is right for you? | usagoldmines.com

I use this $18 box to safely plug in all my outdoor smart devices | usagoldmines.com

The best external drives: 9 top picks for portable storage | usagoldmines.com

WWDC 2025: What to Expect From tvOS 26 Juli Clover | usagoldmines.com

Senate response to White House budget for NASA: Keep SLS, nix science Eric Berger | usagoldmines.com

Samsung Slams $150 Off Galaxy Ring With Any Smartwatch Trade Kellen | usagoldmines.com

Mint Mobile Cuts $800 Off a Pixel 9 With 2 Years of Service Kellen | usagoldmines.com

Meta AI's experimental new smart glasses can see everything you do and even tell how you feel about ...

Google's Chrome Browser Gets 'Highest Score Ever' on Speedometer Performance Test Juli Clover | usag...

Apple Watch Control Center May Support Third-Party App Shortcuts in watchOS 26 Juli Clover | usagold...

What NOT to expect at Apple's WWDC 2025 - three things you definitely won't see philip.berne@futuren...

AMD’s RX 9060 XT is a budget beast, if you can find it at MSRP | usagoldmines.com

Stop Using These Recalled Bowflex Adjustable Dumbbells Now Meredith Dietz | usagoldmines.com

Discord CTO says he’s “constantly bringing up enshittification” during meetings Scharon Harding | us...

Why an Apple TV Box Is More Private Than Your Smart TV (but Not Perfect) Justin Pot | usagoldmines.c...

WWDC 2025: All the Rumors About visionOS 26 Juli Clover | usagoldmines.com

Want to run a GeForce RTX 5090 on your ultra-thin laptop? This Thunderbolt 5 eGPU enclosure can make...

What would happen if Trump retaliated against Musk’s companies? Eric Berger | usagoldmines.com

9 menial tasks ChatGPT can handle for you in seconds, saving hours | usagoldmines.com

Free yourself from summer chores with Dreame’s Z1 Pro pool cleaner | usagoldmines.com

Apple's Long-Rumored 'homeOS' Possibly Trademarked Ahead of WWDC Joe Rossignol | usagoldmines.com

Nvidia will sell a special version of its most powerful GPU to China to skirt around US export restr...

Volvo launches the first smart seatbelt that uses sensors to provide the perfect tension | usagoldm...

Nvidia RTX 5060/5060 Ti review: You can have “affordable” or “future-proof.” Pick one. Andrew Cunnin...

Google releases updated Gemini 2.5 Pro, says it’s the “most intelligent model yet” Ryan Whitwam | us...

How Insurance Companies Use Drones to Raise Your Rates (and What to Do About It) Jeff Somers | usago...

PlayStation Adds Apple Pay Support for PS4 and PS5 Store Purchases Juli Clover | usagoldmines.com

Amazon Has Low Prices on Apple Pencil Pro ($99) and AirTag 4-Pack ($74.99) Mitchel Broussard | usago...

Forget the RTX 5090, this monster is Nvidia's fastest GPU ever manufactured - but it will cost you a...

Microsoft’s Surface Pro pricing is a ripoff | usagoldmines.com

Upcoming Windows 11 feature aims to smartly extend laptop battery life | usagoldmines.com

Fanttik Aero X review: This robotic pool cleaner is an underwater monster | usagoldmines.com

Samsung Brings Sleep Apnea Feature on Galaxy Watch to Total of 70 Markets Tim | usagoldmines.com

Here’s the Crazy Arc Pulse Case for Galaxy S25 Ultra Kellen | usagoldmines.com

These Smart Tech Gadgets Make Great Father’s Day Gifts Amanda Blum | usagoldmines.com

Peloton Is Launching Its Own Resale Platform, and It'll Be Much Better Than Facebook Marketplace Lin...

My Favorite Adjustable Dumbbell Workout Only Takes 15 Minutes Meredith Dietz | usagoldmines.com

Here's How Many iPhones Are Running iOS 18 Juli Clover | usagoldmines.com

'We created a new Airbnb' – here's what the app's big redesign means for how you travel and where yo...

Sony announces Project Defiant, its first-ever wireless fight stick controller designed for PS5 and ...

Have an iPhone but not iOS 18 yet? You’re in the minority jacob.krol@futurenet.com (Jacob Krol) | us...

Reddit sues Anthropic over AI scraping that retained users’ deleted posts Ashley Belanger | usagoldm...

Nintendo warns Switch 2 GameChat users: “Your chat is recorded” Kyle Orland | usagoldmines.com

Peloton Is Launching Its Own Resale Platform, and It'll Be Much Better Than Facebook Marketplace Lin...

Apple Watch Gets Snapchat App Juli Clover | usagoldmines.com

MPA presses for VPNs to have a role in anti-piracy row in Europe chiara.castro@futurenet.com (Chiara...

Hisense's new portable 4K laser projector takes the fight to LG and Samsung, with bright, colorful i...

Alien: Earth finally has an official trailer, and it teases threats even bigger than the dreaded Xen...

PS5’s Thief VR could make me love my PSVR 2 again | usagoldmines.com

Fake DocuSign and Gitcode sites are tricking victims into downloading malware - here's what you need...

Fujifilm teaser suggests the rumored X-E5 is imminent – and it looks like an affordable X100VI alter...

What solar? What wind? Texas data centers build their own gas power plants Dylan Baddour, Arcelia Ma...

Microsoft is adding a simpler text editor than Notepad to Windows 11 soon | usagoldmines.com

Google Drive gets AI-generated summaries of changes made to files | usagoldmines.com

Save $300 on Acer’s productivity laptop with extra-long battery life | usagoldmines.com

I Ranked This Tiny, Cheap Robot Vacuum Higher Than a Dyson That Costs Three Times More Amanda Blum |...

This Self-Propelled Lawn Mower Is at Its Lowest Price Ever Naima Karp | usagoldmines.com

Apple Watch Gets One Crucial Fitness Metric Wrong, Researchers Say Hartley Charlton | usagoldmines.c...

HomePod Turns 8: Here's When to Expect New Models Joe Rossignol | usagoldmines.com

FBI warns Play ransomware hackers have hit nearly a thousand US firms | usagoldmines.com

Stephen Graham's powerful drama Adolescence has performed so well for Netflix that it's beaten Stran...

Cisco warns over worrying security flaws in ISE affecting AWS, Azure cloud deployments - here's what...

Final Fantasy Tactics remaster officially announced with a Nintendo Switch 2 version confirmed for S...

Summer Game Fest 2025 live build-up: where to watch and everything you need to know before the Geoff...

“In 10 years, all bets are off”—Anthropic CEO opposes decadelong freeze on state AI laws Benj Edward...

Xenomorphs are back and bad as ever in Alien: Earth trailer Jennifer Ouellette | usagoldmines.com

Disney’s free streaming ‘perks’ are just insulting | usagoldmines.com

Get these ultra-fast USB-C cables on sale, now 2 for only $12 | usagoldmines.com

Five Shows to Watch While You Wait for the Next Season of 'Hacks' Stephen Johnson | usagoldmines.com

Someone Built an AI Agent for the iPhone Before Apple Could David Nield | usagoldmines.com

iPhone Users Say Mail App Suddenly Showing Blank Screen on iOS 18.5 Joe Rossignol | usagoldmines.com

Amazon Takes Up to $65 Off 11th Gen iPad, Starting at $299 Mitchel Broussard | usagoldmines.com

Apple Arcade Adding Four More Games, Including Angry Birds Bounce Joe Rossignol | usagoldmines.com

More than 3 million records, 12TB of data exposed in major app builder breach | usagoldmines.com

Silent Hill f gets an official release date and a creepy PS5 gameplay trailer | usagoldmines.com

NYT Connections hints and answers for Friday, June 6 (game #726) | usagoldmines.com

NYT Strands hints and answers for Friday, June 6 (game #460) | usagoldmines.com

Quordle hints and answers for Friday, June 6 (game #1229) | usagoldmines.com

Can UK businesses balance AI ambitions with sustainability obligations? | usagoldmines.com

Your Amazon delivery person might soon be a robot, which isn't as terrible as it sounds lance.ulanof...

AI is growing up: how to guide it from experimental child to trusted enterprise adult | usagoldmine...

The best free VPNs: 5 no-cost top picks | usagoldmines.com

Want stronger online security? Think like Gen Z | usagoldmines.com

Today’s best laptop deals: Save big on work, school, home use, and gaming | usagoldmines.com

This Anker docking station doubles as a monitor stand and it’s 20% off | usagoldmines.com

Alienware’s elegant wireless gaming mouse is down to its best-ever price | usagoldmines.com

This Tool for Runners Quickly Measures the Incline of Any Hill Beth Skwarecki | usagoldmines.com

The Google Pixel Tablet Is $140 Off Right Now Pradershika Sharma | usagoldmines.com

Apple Study: App Store Ecosystem Generated $1.3 Trillion Globally in 2024 Juli Clover | usagoldmines...

Take Control of Favicons in Safari's Favorites Bar Tim Hardwick | usagoldmines.com

Ballerina star Norman Reedus didn't seek advice from Keanu Reeves about joining the John Wick univer...

Update Chrome now! Your PC is at risk from this zero-day exploit | usagoldmines.com