Friday, February 3, 2023
  • Events
  • Interviews
  • Jobs
  • Opinion
  • Whitepapers
  • Glossary
  • Community Forum
  • Web Hosting Directory
  • Login
  • Register
Cloud7 News
  • Cloud Computing
  • Web Hosting
  • Data Center
  • Linux
  • Cybersecurity
  • More
    • Network/Internet
    • Windows
    • Software
    • Hardware
    • Blockchain
    • Policy/Legislation
    • How-Tos
    • Troubleshooting
No Result
View All Result
Cloud7 News
  • Cloud Computing
  • Web Hosting
  • Data Center
  • Linux
  • Cybersecurity
  • More
    • Network/Internet
    • Windows
    • Software
    • Hardware
    • Blockchain
    • Policy/Legislation
    • How-Tos
    • Troubleshooting
No Result
View All Result
Cloud7 News
No Result
View All Result

Home > Cybersecurity > How Kinsing malware is used in Kubernetes environments

How Kinsing malware is used in Kubernetes environments

Kinsing malware is used in many ways in Kubernetes environments, two of them being finding vulnerabilities in images and taking advantage of poorly configured PostgreSQL.


Ezgi Koc Ezgi Koc
January 10, 2023
2 min read
How Kinsing malware is used in Kubernetes environments
  • Linux devices are being targeted by the well-known spyware Kinsing in order to steal cryptocurrency.
  • There are two types of attacks usually used in real-life cyberattacks that can be avoided with multiple methods.
  • The two attacks hackers utilize with Kinsing in Kubernetes clusters are finding a vulnerability in images as well as exploiting poorly configured PostgreSQL.

Kinsing is well-known spyware that targets Linux systems to steal cryptocurrency. Kinsing is a popular tool in Kubernetes clusters because it employs several distinctive strategies for settings like these. Sunders Bruskin, a Security Researcher of Microsoft Defender for Cloud published an article talking about Kinsing, specifically the initial access techniques in Kubernetes environments. He includes the ways in which Kinsing exploits weaknesses:

Methods of exploitation

Method 1: finding a vulnerability in images

Many images have remote code execution flaws that may be exploited by attackers with network access to launch their attacks. These are a few instances of programs that were abused and had vulnerable versions:

  • PHPUnit
  • Liferay
  • Oracle WebLogic
  • WordPress

Oracle released advisories about several high-severity vulnerabilities in 2020 that allowed remote code execution (CVE-2020-14882, CVE-2020-14750, and CVE-2020-14883). To exploit these vulnerabilities, hackers start with searching a large number of IP addresses for an open port that corresponds to the WebLogic default port (7001). If there is a vulnerability detected, hackers can use it to launch their malicious payload, such as Kinsing. Bruskin says:

«Recently, we identified a widespread campaign of Kinsing that targeted vulnerable versions of WebLogic servers. »

To avoid this move, use the most recent versions of the images and only trust images from official repositories.

Method 2: Exploiting poorly configured PostgreSQL

Using the ‘trust authentication’ setting is the first misconfiguration. the official PostgreSQL website states:

« When trust authentication is specified, PostgreSQL assumes that anyone who can connect to the server is authorized to access the database with whatever database user name they specify (even superuser names) »

Allowing access to a broad variety of IP addresses puts the PostgreSQL container at risk. To avoid being caught off guard by this method you can use Microsoft Defender for Cloud.

 

Microsoft Defender for Cloud alerting the user of suspicious activity
Microsoft Defender for Cloud alerts the user of suspicious activity

Exploiting weak images and taking advantage of excessive Internet exposure are two methods that hackers use in real-life cyberattacks on Kubernetes clusters. Without adequate security measures, users’ services and machines might be vulnerable to assault from outsiders. If a firm wants to be as safe as possible against security breaches, it’s very important to periodically update its software, and secure configurations.

Ways attackers abuse systems and how to avoid them
Ways attackers abuse systems and how to avoid them

See more Cybersecurity News


Tags: Malware
Ezgi Koc

Ezgi Koc

Ezgi Koc is an editor at Cloud7 News. She graduated from Ege University with a bachelor's degree in English Language and Literature. She had a great interest in technology, both hardware and software, since her childhood and decided to pursue a career that would enable her to broaden her horizons in this field. She is very passionate about video games as a Twitch affiliate and streams games in her free time.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

Next Post
Oxford Ionics raises £30m to help quantum computing

Oxford Ionics raises £30m to help quantum computing

Related News

LockBit encryptor source code is updated

LockBit encryptor source code is updated

February 3, 2023 4:40 pm
Fortinet is expanding its SOC offerings portfolio

Fortinet is expanding its SOC offerings portfolio

February 3, 2023 2:00 pm
Radware announces a new partner program

Radware announces a new partner program

February 3, 2023 1:30 pm
APTs are looking for developers to hire with hefty paychecks

APTs are looking for developers to hire with hefty paychecks

February 1, 2023 2:30 pm
Get free daily newsletters from Cloud7 News Get the Cloud7 Newsletter
Select list(s):

Check your inbox or spam folder to confirm your subscription.

By subscribing, you agree to our
Copyright Policy and Privacy Policy

Get the free newsletter

Subscribe to receive the latest IT business updates straight to your inbox.

Select list(s):

Check your inbox or spam folder to confirm your subscription.

Editor's Choice

What’s new in Linux kernel 6.2 rc6?

10 Best Web Hosting Services of 2023

Ubuntu 22.04 LTS is available for download. What is new?

CERN and Fermilab recommend AlmaLinux

7 best hosting control panels of 2023

How to update Linux Kernel without rebooting?

7 best Linux mail servers of 2023

7 best cPanel alternatives for 2023

7 best Linux web browsers for 2023

7 best CentOS alternatives

7 best Linux server distros of 2023

Interview with Igor Seletskiy on AlmaLinux

How to create a VM on VMware Workstation

Recent News

  • LockBit encryptor source code is updated
  • LibreOffice 7.5 Community is released. What’s new?
  • NTT to add Palo Alto Networks’ solution to its portfolio
  • Gcore announces partnership with Super Protocol
  • Fortinet is expanding its SOC offerings portfolio

Cloud7 News
Cloud7 is a news source that publishes the latest news, reviews, comparisons, opinions, and exclusive interviews to help tech users of high-experience levels in the IT industry.

EXPLORE

  • Web Hosting
  • Cloud Computing
  • Data Center
  • Cybersecurity
  • Linux
  • Network/Internet
  • Software
  • Hardware
  • How-Tos
  • Troubleshooting

RESOURCES

  • Events
  • Interviews
  • Jobs
  • Opinion
  • Whitepapers
  • Glossary
  • Community Forum
  • Web Hosting Directory

Get the Cloud7 Newsletter

Get FREE daily newsletters from Cloud7 delivering the latest news and reviews.

  • About
  • Privacy & Policy
  • Copyright Policy
  • Contact

© 2023, Cloud7 News. All rights reserved.

No Result
View All Result
  • Cloud Computing
  • Web Hosting
  • Data Center
  • Linux
  • Cybersecurity
  • More
    • Network/Internet
    • Windows
    • Software
    • Hardware
    • Blockchain
    • Policy/Legislation
    • How-Tos
    • Troubleshooting
  • Events
  • Interviews
  • Jobs
  • Opinion
  • Whitepapers
  • Glossary
  • Community Forum
  • Web Hosting Directory

© 2023, Cloud7 News. All rights reserved.

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Sign Up with Facebook
Sign Up with Google
Sign Up with Linked In
OR

Fill the forms below to register

*By registering into our website, you agree to the Terms & Conditions and Privacy Policy.
All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.