"Cloud Security Alert: Kinsing Actors Exploit Linux Flaw for Breaching Environments"

1 min read
Source: The Hacker News
"Cloud Security Alert: Kinsing Actors Exploit Linux Flaw for Breaching Environments"
Photo: The Hacker News
TL;DR Summary

Threat actors associated with Kinsing are exploiting the recently disclosed Linux privilege escalation flaw, Looney Tunables, in a new experimental campaign aimed at breaching cloud environments. The attackers are also extracting credentials from the Cloud Service Provider (CSP), marking the first documented instance of active exploitation of Looney Tunables. Kinsing actors have a history of quickly adapting their attack chains to exploit newly disclosed security flaws, and in this case, they are using a critical remote code execution vulnerability in PHPUnit to gain initial access. The ultimate goal of the attack is to extract CSP credentials for future attacks, indicating a potential broadening and intensification of the Kinsing operation in cloud-native environments.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

1 min

vs 2 min read

Condensed

69%

366112 words

Want the full story? Read the original article

Read on The Hacker News