Get a Pentest and security assessment of your IT network.

News

Siloscape, first known malware that drops a backdoor into Kubernetes clusters

Siloscape is a new strain of malware that targets Windows Server containers to execute code on the underlying node and spread in the Kubernetes cluster. The attack chain starts through attacks on web servers and other cloud applications, then the hackers leverage container escape techniques to execute. Then the malicious code searches for the kubectl.exe binary by name using regular expression on the host, using the global link to the hosts. The malware impersonates CExecSvc.exe to obtain SeTcbPrivilege privileges, then creates a symbolic link to its local containerized X drive.”]

Source: https://securityaffairs.co/wordpress/118690/cyber-crime/siloscape-backdoor-kubernetes-clusters.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Botnet authors use Evernote account as C&C Server

News

Canadian agency breached as hackers exploit CVE-2017-5638 flaw in Apache Struts 2