Skip to content
How Did Aqua Catch a Cryptomining Attack Hiding in Memory?
Sign in
Contact
Support
We're hiring!
Platform
Aqua Platform
Runtime Powered Cloud Security
Monitor behavior, detect exploitable risk, enforce policy and contain threats across the application lifecycle.
Platform overview
Code Security
Scanning & Assurance
Scan artifacts across the entire software development lifecycle
Software Supply Chain Security
Protect your code, tools, and processes
Vulnerability Management
Advanced Code-to-Cloud vulnerability management to reduce noise and fix fast
Runtime Security
Container Security
Full lifecycle advanced protection for containerized applications
Cloud Workload Protection (CWPP)
Runtime protection for every cloud native workload
Hybrid-Cloud & Multi-Cloud Security
Code to Cloud security for hybrid and multi-cloud deployments
GenAI Application Security
Secure GenAI Applications from Code to Runtime
Posture Management
CI/CD Pipeline Security
Automate DevSecOps
Kubernetes Security
Holistic Kubernetes Security for the Enterprise
Cloud Security Posture Management
Extend traditional CSPM with workload visibility
Solutions
Solutions
Monitor
Monitor Behavior Across Every Environment
Detect
Detect Exploitable Risk and Active Attacks
Enforce
Enforce Policy Inline at the Point of Execution
Contain
Contain Threats and Maintain Control
Compliance
Prove Compliance in the Most Regulated Environments
Hybrid and Multi-Cloud
Secure Applications Across Hybrid and Multi-Cloud
Industry
Federal
Protect Highly Sensitive Data
Financial Services
Protect FinServs From Cyber Threats
Resources
The best of cloud native
Aqua Blog
Expert insight, best practices and advice on cloud native security, trends, threat intelligence and compliance
Read the Blog
Resources
Resources Center
eBooks, Data sheets, Whitepapers, Webinars, and much more
The Cloud Native Channel
Cloud native security webinars & videos
Aquademy
The Aqua academy
Cloud Native Wiki
The educational center for everything cloud native
Company
Recognized Leadership
CISO Choice Awards
Winner for Cloud Workload Protection Platform (CWPP)
Forrester Consulting: The Total Economic Impact™ of Aqua CNAPP
90% Reduction in vulnerability research and detection time
Frost & Sullivan CNAPP report
Top innovation leader
About Us
Newsroom
Customers
Partners
Careers
Support
Services
Upcoming Events
Connect
Contact
Twitter
Facebook
Linkedin
Instagram
News
Aqua Security Turns Runtime Intelligence into Action with Agentic Response, Debuts Risk Dashboards
Aqua Security Doubles Down on Runtime to Deliver Measurable Cloud Risk Reduction
ActiveState Joins Trivy Partner Connect to Cut CVE Noise and Reduce Alert Fatigue for Developers
Get Started
Aqua Cloud Native Blog
› Tags: Security Threats
Expert insight, best practices and advice on cloud native security, trends, threat intelligence and compliance.
SECURITY RESEARCH
TeamTNT’s Docker Gatling Gun Campaign
Security Threat
Long time no see, Aqua Nautilus researchers have identified a new campaign in the making by TeamTNT, a notorious hacking group. In this campaign, TeamTNT appears to be returning to its roots while preparing for a large-scale attack on cloud native environments. The group is currently targeting exposed Docker daemons to deploy Sliver malware, a …
SECURITY RESEARCH
AWS CDK Risk: Exploiting a Missing S3 Bucket Allowed Account Takeover
Security Threat
In June 2024, we uncovered a security issue related to the AWS Cloud Development Kit (CDK), an open-source project. This discovery adds to the six other vulnerabilities we discovered within AWS services. The impact of this issue could, in certain scenarios (outlined in the blog), allow an attacker to gain administrative access to a target AWS account, …
SECURITY RESEARCH
perfctl: A Stealthy Malware Targeting Millions of Linux Servers
Security Threat
In this blog post, Aqua Nautilus researchers aim to shed light on a Linux malware that, over the past 3-4 years, has actively sought more than 20,000 types of misconfigurations in order to target and exploit Linux servers. If you have a Linux server connected to the internet, you could be at risk. In fact, …
SECURITY RESEARCH
CUPS: A Critical 9.9 Linux Vulnerability Reviewed
Security Threat
In the past couple of days there has been many troubling publications and discussions about a mysterious critical Linux vulnerability allowing remote code execution. While this headline is very alarming, after diving into details there are many preconditions that cool down the level of alertness. Aqua Security researchers have looked into the content that was …
SECURITY RESEARCH
Hadooken Malware Targets Weblogic Applications
Aqua Nautilus researchers identified a new Linux malware targeting Weblogic servers. The main payload calls itself Hadooken which we think is referring to the attack “surge fist” in the Street Fighter series. When Hadooken is executed, it drops a Tsunami malware and deploys a cryptominer. In this blog, we explain the malware, its components, and …
SECURITY RESEARCH
PG_MEM: A Malware Hidden in the Postgres Processes
Aqua Nautilus researchers have uncovered PG_MEM, a new PostgreSQL malware, that brute forces its way into PostgreSQL databases, delivers payloads to hide its operations, and mines cryptocurrency. In this blog, we explain this attack, the techniques used by the threat actor, and how to detect and protect your environments.
SECURITY RESEARCH
Panamorfi: A New Discord DDoS Campaign
Aqua Nautilus researchers uncovered a new Distributed Denial of Service (DDoS) campaign dubbed ‘Panamorfi’, utilizing the Java written minecraft DDoS package – mineping – the threat actor launches a DDoS. Thus far we’ve only seen it deployed via misconfigured Jupyter notebooks. In this blog we explain about this attack, the techniques used by the threat …
SECURITY RESEARCH
Kubernetes Exposed: Exploiting the Kubelet API
Kubelet API is a vital component in Kubernetes clusters that manages pods and their containers on each node. While it is not typically intended for direct user interaction, many DevOps teams may utilize the Kubelet API for debugging and direct node communication. However, exposing the Kubelet API to the public internet while enabling anonymous unauthenticated …
SECURITY RESEARCH, VULNERABILITY MANAGEMENT
Muhstik Malware Targets Message Queuing Services Applications
Threat Alert
Aqua Nautilus discovered a new campaign of Muhstik malware targeting message queuing services applications, specifically the Apache RocketMQ platform. Our investigation revealed that the attackers downloaded the known malware Muhstik onto the compromised instances by exploiting a known vulnerability in the platform. In this blog, we will explore how the attackers exploit the existing vulnerability …
SECURITY RESEARCH
Linguistic Lumberjack: Understanding CVE-2024-4323 in Fluent Bit
Linguistic Lumberjack is a new critical severity vulnerability (CVE-2024-4323) that affects Fluent Bit versions 2.0.7 through 3.0.3. The vulnerability involves a memory corruption error, potentially leading to denial of service, information disclosure, or remote code execution.
SECURITY RESEARCH
Employee Personal GitHub Repos Expose Internal Azure and Red Hat Secrets
Security Threat
What happens when employees at some of the world’s largest organizations like Microsoft and RedHat use personal GitHub repos for their side projects? They can unknowingly expose corporate secrets and credentials opening the doors for a security incident. Unfortunately, this isn’t just a hypothetical situation.
CONTAINER SECURITY
CVE-2024-3094: Newly Discovered Backdoor in XZ tools
The xz-utils is a popular compression tool used widely across Linux systems, indicating its critical role in the software ecosystem. The xz-utils backdoor, discovered on March 29, 2024, exposes systems to potential backdoor access and remote code execution. It specifically targets versions 5.6.0 and 5.6.1 of xz-utils on systems using glibc, systemd, and patched OpenSSH. …
Page 2 of 10
‹ Prev
1
2
3
4
5
6
Next ›
Need to secure enterprise workloads?
Aqua Cloud Native Application Protection Platform (CNAPP)
Go cloud native with the experts!
Get Demo