Skip to content
How Did Aqua Catch a Cryptomining Attack Hiding in Memory?
Sign in
Contact
Support
We're hiring!
Platform
Aqua Platform
Runtime Powered Cloud Security
Monitor behavior, detect exploitable risk, enforce policy and contain threats across the application lifecycle.
Platform overview
Code Security
Scanning & Assurance
Scan artifacts across the entire software development lifecycle
Software Supply Chain Security
Protect your code, tools, and processes
Vulnerability Management
Advanced Code-to-Cloud vulnerability management to reduce noise and fix fast
Runtime Security
Container Security
Full lifecycle advanced protection for containerized applications
Cloud Workload Protection (CWPP)
Runtime protection for every cloud native workload
GenAI Application Security
Secure GenAI Applications from Code to Runtime
Posture Management
CI/CD Pipeline Security
Automate DevSecOps
Kubernetes Security
Holistic Kubernetes Security for the Enterprise
Cloud Security Posture Management
Extend traditional CSPM with workload visibility
Solutions
Solutions
Monitor
Monitor Behavior Across Every Environment
Detect
Detect Exploitable Risk and Active Attacks
Enforce
Enforce Policy Inline at the Point of Execution
Contain
Contain Threats and Maintain Control
Compliance
Prove Compliance in the Most Regulated Environments
Hybrid and Multi-Cloud
Secure Applications Across Hybrid and Multi-Cloud
Industry
Federal
Protect Highly Sensitive Data
Financial Services
Protect FinServs From Cyber Threats
Resources
The best of cloud native
Aqua Blog
Expert insight, best practices and advice on cloud native security, trends, threat intelligence and compliance
Read the Blog
Resources
Resources Center
eBooks, Data sheets, Whitepapers, Webinars, and much more
The Cloud Native Channel
Cloud native security webinars & videos
Aquademy
The Aqua academy
Cloud Native Wiki
The educational center for everything cloud native
Company
Recognized Leadership
CISO Choice Awards
Winner for Cloud Workload Protection Platform (CWPP)
Forrester Consulting: The Total Economic Impact™ of Aqua CNAPP
90% Reduction in vulnerability research and detection time
Frost & Sullivan CNAPP report
Top innovation leader
About Us
Newsroom
Customers
Partners
Careers
Support
Services
Upcoming Events
Connect
Contact
Twitter
Facebook
Linkedin
Instagram
News
Aqua Security Named “Cloud Security Platform of the Year” in 10th Annual CyberSecurity Breakthrough Awards Program
Aqua Security Turns Runtime Intelligence into Action with Agentic Response, Debuts Risk Dashboards
Aqua Security Doubles Down on Runtime to Deliver Measurable Cloud Risk Reduction
Get Started
Aqua Cloud Native Blog
› Tags: Security Threats
Expert insight, best practices and advice on cloud native security, trends, threat intelligence and compliance.
SECURITY RESEARCH
Threat Alert: An Attack Against a Docker API Leads To Hidden Cryptominers
Following an attack against a misconfigured Docker API port, the research team at Aqua Security performed an in-depth examination of the Docker Hub account from which the image was pulled. The examination was done by dynamically scanning for hidden threats in the container images hosted in that specific Docker Hub account (ubuntuz) and comparing them …
SECURITY RESEARCH
Mitigating High Severity CVEs Affecting SaltStack on Public Clouds
CVE-2020-11651/11652
Two high-severity CVEs in the SaltStack platform were published last week by researchers at F-Secure. These vulnerabilities can enable remote code execution (RCE), which lets attackers remotely execute commands on the Salt leader node. This results in a full compromise of the host and can expose sensitive information within the cloud environment. To address this, …
SECURITY RESEARCH
Threat Alert: Kinsing Malware Attacks Targeting Container Environments
Lately we’ve been witnessing a rise in the number of attacks that target container environments. We’ve been tracking an organized attack campaign that targets misconfigured open Docker Daemon API ports. This persistent campaign has been going on for months, with thousands of attempts taking place nearly on a daily basis. These are the highest numbers …
SECURITY RESEARCH
Threat Alert: Attack Vector Uses Containers to Methodically Target Cloud Resources
The Aqua Research team has identified a new attack vector that points to an evolution in attacks’ techniques and capabilities. In these attacks, the attackers leverage containers as an entry point to discover and spread to other resources used within cloud accounts. The attackers deployed a clean Ubuntu container, mounted the host file system, which …
SECURITY RESEARCH
Threat Alert: Exploiting Open Docker Daemons for DDoS Attacks
Threat Alert
Aqua’s research team continuously investigates and analyzes the anatomy of new attacks in the wild. Recently, we identified attacks that exploited misconfigured open Docker daemons, where attackers were actively using this attack vector to hijack environments in order to launch targeted DDoS attacks. Each of the attacks were carried out using a botnet of containers, …
SECURITY RESEARCH
Maneuver Docker API for Host Takeover
Threat Alert
Docker clients can communicate with the daemon either locally, via a unix socket, or over a network via a TCP socket. Aqua’s research team discovered an interesting attack vector running on top of an unsecured Docker socket API. Instead of running a malicious Docker image, the attacker changes the traditional entry-point to take control over …
SECURITY RESEARCH
CVE-2019-14287 sudo Vulnerability Allows Bypass of User Restrictions
CVE-2019-14287
A new vulnerability was discovered earlier this week in the sudo package. Sudo is one of the most powerful and commonly used utilities installed on almost every UNIX and Linux-based operating system.
SECURITY RESEARCH
DNS Spoofing on Kubernetes Clusters
In this post I’ll describe how an attacker, who manages to run malicious code on a cluster can, with no special permissive permissions, successfully spoof DNS responses to all the applications running on the cluster, and from there execute a MITM (Man In The Middle) on all network traffic of pods.
SECURITY RESEARCH
Kubernetes Pod Escape Using Log Mounts
Kubernetes has many moving parts, and sometimes combining them in certain ways can create unexpected security flaws. In this post you’ll see how a pod running as root and with a mount point to the node’s /var/log directory can expose the entire contents of its host filesystem to any user who has access to its …
SECURITY RESEARCH
Crypto-Mining Malware Outsmarting Image Scanners
In previous crypto-mining attacks, we observed hackers investing little to no effort in hiding their malicious activities. They just ran the malicious container with all of its scripts and configuration files in clear text. This made the analysis of their malicious intent fairly easy.
SECURITY RESEARCH
CVE-2019-11246: Another kubectl Path Traversal Vulnerability Disclosed
A new vulnerability (CVE-2019-11246) was disclosed that enables path traversal in kubectl, the popular command line interface for running commands on Kubernetes clusters. What’s interesting about this CVE is that we’ve already seen two previous variations of the same vulnerability disclosed and patched. Read on to learn how that happened.
SECURITY RESEARCH
CVE-2019-5021: Alpine Docker Image ‘null root password’ Vulnerability
A new vulnerability that impacts Alpine Docker images was published last week. The vulnerability is due to the ‘root’ user password which is set, by default, to NULL on Alpine Docker images from version 3.3 or higher.
Page 10 of 10
‹ Prev
6
7
8
9
10
Need to secure enterprise workloads?
Aqua Cloud Native Application Protection Platform (CNAPP)
Go cloud native with the experts!
Get Demo