Kubernetes Cloud Clusters Face Cyberattacks via Argo Workflows
#1
Information 
Quote:Kubernetes clusters are being attacked via misconfigured Argo Workflows instances, security researchers are warning.
 
Argo Workflows is an open-source, container-native workflow engine for orchestrating parallel jobs on Kubernetes – to speed up processing time for compute-intensive jobs like machine learning and big-data processing. It’s also used to simplify container deployments in general. Kubernetes, meanwhile, is a popular container-orchestration engine for managing cloud deployments.
 
Malware operators are dropping cryptominers into the cloud via Argo thanks to some instances being publicly available via dashboards that don’t require authentication for outside users, according to an analysis from Intezer. These misconfigured permissions thus can allow threat actors to run unauthorized code in the victim’s environment.
 
“In many instances, permissions are configured which allow any visiting user to deploy workflows,” according to the Intezer analysis, published Tuesday. “In instances when permissions are misconfigured, it is possible for an attacker to access an open Argo dashboard and submit their own workflow.”
 
Researchers said the misconfigurations can also expose sensitive information such as code, credentials and private container-image names (which can be used to assist in other kinds of attacks).

Intezer’s scan of the web found scads of unprotected instances, operated by companies in several industries, including technology, finance and logistics.
 
“We have identified infected nodes and there is the potential for larger-scale attacks due to hundreds of misconfigured deployments,” according to Intezer. In one case, bad code was running on an exposed cluster in Docker Hub for nine months before being discovered and removed.

Read more: Kubernetes Cloud Clusters Face Cyberattacks via Argo Workflows | Threatpost
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
TinyWall 3.5.1
TinyWall 3.5.1 ...harlan4096 — 15:17
Microsoft Edge Removes Master Password F...
Microsoft has remo...harlan4096 — 15:15
QOwnNotes
26.6.4 Added an o...Kool — 06:08
Adobe Acrobat Reader DC 26.001.21651
Adobe Acrobat Read...harlan4096 — 18:17
Privazer 4.0.123 (05 June 2026)
v4.0.123 (05 June ...harlan4096 — 07:35

[-]
Birthdays
Today's Birthdays
avatar (51)smudloquask
avatar (46)benchJem
Upcoming Birthdays
avatar (49)rapedDow
avatar (44)Johnsonsyday
avatar (49)Groktus
avatar (41)efodo
avatar (39)Tedscolo
avatar (46)brakasig
avatar (45)JamesReshy
avatar (47)Francisemefe
avatar (40)leoniDup
avatar (39)Patrizaancem
avatar (39)biobdam
avatar (42)zacforat
avatar (47)NemrokReks
avatar (38)Barrackleve
avatar (40)Julioagopy
avatar (50)aolaupitt2558
avatar (48)vadimTob
avatar (38)leannauu4
avatar (40)storoBox
avatar (48)kinotHeemn
avatar (39)Ceballos1976
avatar (40)efynu
avatar (32)horancos

[-]
Online Staff
There are no staff members currently online.

>