Illicit crypto-miners pouncing on lazy DevOps configs that leave clouds vulnerable
Up to a quarter of all cloud users are at risk of having their computing resources stolen and used to illicitly mine for cryptocurrency, after crims cooked up a campaign that targets publicly accessible DevOps tools.
Wiz Threat Research spotted the campaign and attributed it to an attacker it named JINX–0132, which it says exploits misconfigurations and vulnerabilities in multiple applications to deploy mining software.
JINX–0132 targets a "wide range" of DevOps tools, but Wiz thinks it prefers ...
Read more at theregister.com