Kubernetes Cloud Clusters Face Cyberattacks via Argo Workflows
#1
Information 
Quote:Kubernetes clusters are being attacked via misconfigured Argo Workflows instances, security researchers are warning.
 
Argo Workflows is an open-source, container-native workflow engine for orchestrating parallel jobs on Kubernetes – to speed up processing time for compute-intensive jobs like machine learning and big-data processing. It’s also used to simplify container deployments in general. Kubernetes, meanwhile, is a popular container-orchestration engine for managing cloud deployments.
 
Malware operators are dropping cryptominers into the cloud via Argo thanks to some instances being publicly available via dashboards that don’t require authentication for outside users, according to an analysis from Intezer. These misconfigured permissions thus can allow threat actors to run unauthorized code in the victim’s environment.
 
“In many instances, permissions are configured which allow any visiting user to deploy workflows,” according to the Intezer analysis, published Tuesday. “In instances when permissions are misconfigured, it is possible for an attacker to access an open Argo dashboard and submit their own workflow.”
 
Researchers said the misconfigurations can also expose sensitive information such as code, credentials and private container-image names (which can be used to assist in other kinds of attacks).

Intezer’s scan of the web found scads of unprotected instances, operated by companies in several industries, including technology, finance and logistics.
 
“We have identified infected nodes and there is the potential for larger-scale attacks due to hundreds of misconfigured deployments,” according to Intezer. In one case, bad code was running on an exposed cluster in Docker Hub for nine months before being discovered and removed.

Read more: Kubernetes Cloud Clusters Face Cyberattacks via Argo Workflows | Threatpost
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
Kubernetes Cloud Clusters Face Cyberattacks via Argo Workflows - by silversurfer - 22 July 21, 12:22

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AntGROUP Inc. / VCap-developer
Ant Download Manager...jasonX — 01:54
Windows 11 Build 26300.8493 Brings Movab...
Microsoft has rele...harlan4096 — 16:55
Google Chrome 148.0.7778.167/168
The security updat...harlan4096 — 07:15
Microsoft Edge 148.0.3967.70
Version 148.0.3967...harlan4096 — 07:12
Vivaldi 7.9 Build 3970.67
Vivaldi 7.9 Build ...harlan4096 — 07:09

[-]
Birthdays
Today's Birthdays
avatar (49)contjrat
Upcoming Birthdays
avatar (28)akiratoriyama
avatar (48)Jerrycix
avatar (40)awedoli
avatar (82)WinRARHowTo
avatar (39)axuben
avatar (40)ihijudu
avatar (50)Mirzojap
avatar (36)idilysaju
avatar (40)GregoryRog
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>