Kubernetes Falls to Cryptomining via Machine-Learning Framework
#1
Information 
Quote:A unique cyberattack campaign that targets Kubeflow, a machine-learning toolkit for Kubernetes, has affected large swathes of container clusters, according to Microsoft.
 
The Kubeflow open-source project is a popular framework for running machine-learning (ML) tasks in Kubernetes. According to an analysis this week, a suspicious Kubeflow image was seen deployed to thousands of clusters in April, all from a single public repository. Closer inspection showed that the image runs a common open-source cryptojacking malware that mines the Monero virtual currency, known as XMRIG.
 
“Nodes that are used for ML tasks are often relatively powerful, and in some cases include GPUs [graphics processors],” explained Yossi Weizman, security research software engineer at Microsoft’s Azure Security Center, in a posting on Wednesday. “This fact makes Kubernetes clusters that are used for ML tasks a perfect target for cryptomining campaigns, which was the aim of this attack.”
 
In terms of how Kubeflow can be used as the entry point for this kind of attack, Weizman noted that Kubeflow can manage the various tasks required to put a ML model into action, such as training ML algorithms. For instance, according to its website, Kubeflow simplifies the many steps required to build and deploy an ML model, including “data loading, verification, splitting, processing, feature engineering, model training and verification, hyperparameter tuning and model serving.”

Read more: https://threatpost.com/kubernetes-crypto...rk/156481/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes
26.4.12  Turned t...Kool — 15:52
Bitdefender 27.0.58.324
Latest version o...harlan4096 — 11:36
Microsoft Edge 147.0.3912.72
Version 147.0.3912...harlan4096 — 11:34
AdGuard VPN for Windows 2.9.1
AdGuard VPN for Wi...harlan4096 — 11:31
Vivaldi 7.9 Build 3970.55
Vivaldi 7.9 Build ...harlan4096 — 11:30

[-]
Birthdays
Today's Birthdays
avatar (49)oapedDow
avatar (42)Sanchowogy
Upcoming Birthdays
avatar (45)wapedDow
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)Toligo
avatar (38)RobertUtelt

[-]
Online Staff
There are no staff members currently online.

>