Hackers have found another way to attack Kubernetes clusters

Hackers have found another way to attack Kubernetes clusters
Cybersecurity researchers have detailed a new attack vector that suppresses cryptomining malware in Kubernetes clusters by exploiting misconfigured Argo Workflows instances. Argo Workflows is an open source workflow engine for Kubernetes that simplifies the process of orchestrating parallel tasks on Kubernetes clusters. Intezer researchers found hundreds of instances of Argo Workflows with misconfigured permissions and observed that many people were being abused by malicious actors.

LaComparacion needs you! We take a look at how our readers are using VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey will take no more than 60 seconds of your time, and you can also choose to be entered into a drawing to win a €100 Amazon voucher or one of five year-long ExpressVPN subscriptions.
Click here to launch the survey in a new window
“We have identified infected nodes and there is the potential for larger-scale attacks due to hundreds of misconfigured deployments. We have spotted exposed instances of Argo workflows belonging to companies across different industries, including technology, finance, and logistics, ”Intezer's Ryan Robinson and Nicole Fishbein note in a joint blog post.

Misconfigured

The researchers argue that even products like Argo Workflows, designed to reduce deployment complexity, can become a source of exploitation if not configured correctly. While searching for such misconfigured instances, the researchers found several that were unprotected or had liberal permission settings that would allow any user to implement workflows. In one cluster, we noticed a popular cryptocurrency mining container being deployed, kannix/monero-miner, which used XMRig to mine Monero cryptocurrency. Incidentally, the researchers note that even though kannix/monero-miner has been removed from Docker Hub, the popular Docker repository still lists at least 45 other crypto-mining containers that have logged millions of downloads.