back to article Illicit crypto-miners pouncing on lazy DevOps configs that leave clouds vulnerable

Up to a quarter of all cloud users are at risk of having their computing resources stolen and used to illicitly mine for cryptocurrency, after crims cooked up a campaign that targets publicly accessible DevOps tools. Wiz Threat Research spotted the campaign and attributed it to an attacker it named JINX–0132, which it says …

  1. Irongut Silver badge

    Insecure defaults and the ability for anyone to reinstall to get them. FFS.

    So don't buy from HashiCorp because they can't write software for toffee. Got it.

    1. SVD_NL Silver badge

      When "secure by default" is simply a buzzword to tick off...

  2. cookiecutter

    Developers!!

    More than half of infosec seems to be putting guardrails Around idiot developers who for some reason have been given the keys to the kingdom after whining about system admins not giving them admin access or refusing to turn off the firewalls

    Agile, DevOps etc are a nightmare. Might as well just hand out all your customer details from day 1, save yourself the developer costs.

    1. Martin M

      Re: Developers!!

      If developers have been given “the keys to the kingdom” and can make changes to prod (or even test) environments without review by someone else who has solid ops and security understanding, then what is happening is not devops.

      But if you are dismissing developers as idiots and whiny, rather than working with them, you’re part of the problem that led to the need to define devops in the first place.

      1. DVG46

        Re: Developers!!

        Yep, basic security, developers have no access to production systems and production support do not have ability modify production code.

  3. ecofeco Silver badge
    Facepalm

    Poetic justice

    If you ask me.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like