Hackers hijack OpenMetadata apps in Kubernetes cryptomining attacks
Attackers use serious vulnerabilities related to remote code execution and authentication to target OpenMetadata workloads in an ongoing Kubernetes cryptomining operation.
Data scientists and engineers can use OpenMetadata, an open-source metadata management platform, to find and classify data assets in their company, such as files, databases, tables, and services.
The security flaws in OpenMedata versions 1.2.4 and 1.3.1 that were exploited in these attacks (CVE-2024-28255, CVE-2024-28847, CVE-2024-28253, CVE-2024-28848, and CVE-2024-28254) were corrected one month ago on March 15.
First to identify the attacks, Microsoft claims that since early April, the five vulnerabilities have been actively used to take control of OpenMedata workloads that are exposed to the Internet and ar...

