Duo Labs set out to measure how many Redis instances were exposed to the Internet and potentially vulnerable to attacks. Redis is intended to be used in trusted environments, and so it ships with a permissive security configuration. Exposing Redis directly to Internet allows attackers to view/modify the stored data. Even more importantly, attackers are able to remotely configure the Redis instance which, as well see in this post, can lead to a complete compromise of the device. After setting up a honeypot to catch attackers, we recorded an attempted attack in just hours.”]
Source: https://duo.com/decipher/over-18000-redis-instances-targeted-by-fake-ransomware

