Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • DeFi
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • Gaming
  • Legal
    • Taxes & Regulation
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Converter
What's Hot

Arizona revives bid for seized crypto reserve fund through House Bill 2324

June 20, 2025

Jupiter halts governance voting to tackle burnout and refocus on innovation

June 20, 2025

Visa Taps Yellow Card for Stablecoin Payments Push Across 20 African Nations

June 20, 2025
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Buy Crypto NewsBuy Crypto News
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    Crypto Market Faces Short-term Bearish Sentiment After Fed Left Interest Rate Unchanged Akin to BoJ

    June 20, 2025

    Bitcoin Reclaiming This Critical Resistance Level Would Be a Big Signal for the Next Leg Up, Says Analyst Michaël van de Poppe

    June 20, 2025

    NEAR Protocol Surges 5% as Buyers Dominate Amid Middle East Tensions

    June 20, 2025

    ‘Ancient’ Bitcoin Supply Now Outpacing Newly Mined BTC: Fidelity Report

    June 19, 2025

    Analyst Predicts 20% Ethereum Price Crash Below $2,000, Here’s Why

    June 20, 2025

    Ethereum whale stakes $18M at a loss, but retail is dumping! – Who’s right?

    June 20, 2025

    Here’s Why ETH is Poised for a Megarally

    June 20, 2025

    Is Ethereum Price Set To Repeat History As 2017 Playbook Returns? Why This Time Could Be Bigger

    June 19, 2025

    Could a nuclear war kill crypto? AI predicts Bitcoin’s fate in doomsday scenario

    June 20, 2025

    Is RXS the Best Low-Cap Bet for the 2025 Bull Market?

    June 20, 2025

    Solana Memecoin About To ‘Blast Through’ All-Time Highs, According to Veteran Crypto Trader

    June 19, 2025

    Solana: 386K SOL sold in 4 days – Traders, watch THESE levels next

    June 19, 2025

    Pepe, BMT, CAKE: Crypto Activity Heats Up

    March 18, 2025

    SHIB Burns Over Half a Billion Tokens, Price Surges Over 7%

    March 17, 2025

    DOGE Sees Massive User Growth: Active Addresses Up 400%

    March 15, 2025

    Shiba Inu (SHIB) Price Analysis: Bullish Hints, Bearish Trend

    March 15, 2025

    Arizona revives bid for seized crypto reserve fund through House Bill 2324

    June 20, 2025

    Jupiter halts governance voting to tackle burnout and refocus on innovation

    June 20, 2025

    Visa Taps Yellow Card for Stablecoin Payments Push Across 20 African Nations

    June 20, 2025

    Analyst Predicts 20% Ethereum Price Crash Below $2,000, Here’s Why

    June 20, 2025
  • DeFi

    Jupiter halts governance voting to tackle burnout and refocus on innovation

    June 20, 2025

    AERO price breaks key resistance as futures open interest hits ATH

    June 20, 2025

    Raydium price forecast after the Upbit listing

    June 20, 2025

    PancakeSwap extends lead as monthly DEX volume tops $500B

    June 19, 2025

    Ethena Labs and Securitize enable 24/7 USDtb-BUIDL swaps

    June 19, 2025
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    Visa Taps Yellow Card for Stablecoin Payments Push Across 20 African Nations

    June 20, 2025

    JZXN Raises Capital via Convertible Notes to Buy Bitcoin

    June 20, 2025

    Russian Power Firm Launches Bitcoin Mining Mutual Investment Fund

    June 20, 2025

    Blockticity Launches L1 on Avalanche to Authenticate $1.2B+

    June 20, 2025

    North Korean Hackers Deploy Python-Based Trojan Targeting Crypto

    June 20, 2025

    Israeli Hacktivists Steal and Burn $90m+ from Iranian Crypo Biz

    June 19, 2025

    ZachXBT warns suspected ZKasino fraudster may be linked to new crypto venture WhiteRock

    June 17, 2025

    Threat Actors Target Victims with HijackLoader and DeerStealer

    June 17, 2025

    Arizona revives bid for seized crypto reserve fund through House Bill 2324

    June 20, 2025

    Jupiter halts governance voting to tackle burnout and refocus on innovation

    June 20, 2025

    Visa Taps Yellow Card for Stablecoin Payments Push Across 20 African Nations

    June 20, 2025

    Analyst Predicts 20% Ethereum Price Crash Below $2,000, Here’s Why

    June 20, 2025
  • Web 3
    1. Web3 News
    2. Gaming
    3. View All

    Doodles NFT Sticker Launch on Telegram Sells Out in 24 Hours

    June 20, 2025

    ZTE showcases full-stack innovations at MWC Shanghai 2025, co-creating an era of AI for all

    June 20, 2025

    Location-Based Gaming NFTs: How GPS and Blockchain Are Changing the Way We Play

    June 20, 2025

    ReggaeEDM Takes The Stage | Web3Wire

    June 19, 2025

    A16z-backed Spekter Games founder shares Telegram gaming ethos

    June 20, 2025

    Crypto Casinos Made Over $80 Billion in 2024

    June 20, 2025

    Avalanche Game ‘Forgotten Playland’ Implements NFTs in Biggest Update Yet

    June 20, 2025

    How Mobile Apps Are Quietly Adopting Web3 Tech

    June 20, 2025

    Arizona revives bid for seized crypto reserve fund through House Bill 2324

    June 20, 2025

    Jupiter halts governance voting to tackle burnout and refocus on innovation

    June 20, 2025

    Visa Taps Yellow Card for Stablecoin Payments Push Across 20 African Nations

    June 20, 2025

    Analyst Predicts 20% Ethereum Price Crash Below $2,000, Here’s Why

    June 20, 2025
  • Legal
    1. Taxes & Regulation
    2. Adoption
    3. View All

    Elizabeth Warren criticizes GENIUS Act over stablecoin concerns ahead of final vote

    June 20, 2025

    Ripple Says Negotiated Settlement Levels the Playing Field

    June 20, 2025

    Coinbase push for crypto-friendly UK gains momentum

    June 20, 2025

    Why Some US Crypto Companies are Favoring Democrats

    June 20, 2025

    Arizona revives bid for seized crypto reserve fund through House Bill 2324

    June 20, 2025

    X transforms into a finance hub but sidesteps crypto—for now

    June 20, 2025

    Ford explores decentralized legal data storage on Cardano blockchain

    June 19, 2025

    Two public firms announce plans to adopt HYPE as primary reserve asset for treasury

    June 19, 2025

    Arizona revives bid for seized crypto reserve fund through House Bill 2324

    June 20, 2025

    Jupiter halts governance voting to tackle burnout and refocus on innovation

    June 20, 2025

    Visa Taps Yellow Card for Stablecoin Payments Push Across 20 African Nations

    June 20, 2025

    Analyst Predicts 20% Ethereum Price Crash Below $2,000, Here’s Why

    June 20, 2025
  • Analysis

    Story (IP) Price Plunges While Trading Volume Spikes Over 200%-What’s Going On?

    June 20, 2025

    Dogecoin Price Prediction: $0.10 Incoming or $1.25 Moonshot?

    June 19, 2025

    Institutional Investors Dump $50,780,000,000 in Stocks in Just One Month Amid US Bond Rating Downgrade and Trump Trade War: S&P Global

    June 19, 2025

    Why Is Cardano (ADA) Price Dropping Today? Here’s What You Need to Know!

    June 19, 2025

    Goldman Sachs Flips Bullish on Ten Stocks – Bank Says These Companies Could Be China’s ‘Magnificent 7’

    June 19, 2025
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What Are Internet Capital Markets? Why Companies Are Launching Meme Coins

    June 16, 2025

    What is a Corporate Bitcoin Treasury? The Strategy Behind Companies Holding Crypto

    May 27, 2025

    What Are Tokenized Real-World Assets? Putting Physical Value On-Chain With RWAs

    May 19, 2025

    Users Taunt Grok After xAI Says Modifications Were Made to Spit out ‘White Genocide’ Claim

    May 16, 2025

    Iran-based crypto exchange hacked for $48M amid cyberattack claims by Israel-linked group

    June 20, 2025

    Iran’s Nobitex loses $100 million to symbolic cyberattack

    June 20, 2025

    Coinbase launches stablecoin payment stack with USDC checkout targeting commerce giants

    June 19, 2025

    Circle’s USDC and BlackRock’s BUIDL spearhead collateral innovation in derivatives markets

    June 19, 2025

    Arizona revives bid for seized crypto reserve fund through House Bill 2324

    June 20, 2025

    Jupiter halts governance voting to tackle burnout and refocus on innovation

    June 20, 2025

    Visa Taps Yellow Card for Stablecoin Payments Push Across 20 African Nations

    June 20, 2025

    Analyst Predicts 20% Ethereum Price Crash Below $2,000, Here’s Why

    June 20, 2025
  • Tools
    • Market Overview
    • Converter
Buy Crypto NewsBuy Crypto News
Home»Security and Privacy»Cryptojacking Campaign Targets DevOps Servers Including Nomad
Cryptojacking Campaign Targets DevOps Servers Including Nomad
Security and Privacy

Cryptojacking Campaign Targets DevOps Servers Including Nomad

June 3, 2025No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Researchers have recently uncovered a concerning trend in the cybersecurity landscape – threat actors are now targeting misconfigured HashiCorp Nomad deployments as an attack vector. HashiCorp Nomad is a popular DevOps platform that allows organizations to deploy and manage containers and non-containerized applications. Alongside Nomad, other infrastructure components such as Gitea, Consul, and Docker API are also being exploited by a threat group identified as JINX-0132 for cryptojacking activities.

According to a report by cloud security provider Wiz, a significant number of cloud environments, around 25%, are utilizing one or more of the targeted technologies. Shockingly, 5% of these environments expose these tools directly to the internet, and among these exposed deployments, 30% are found to be misconfigured. This creates a ripe opportunity for threat actors to exploit vulnerabilities and misconfigurations in these DevOps tools.

One of the key tactics employed by the JINX-0132 attackers involves leveraging Nomad’s job queue feature, which allows users to submit tasks for execution by nodes registered with the Nomad server. By default, any user with access to the Nomad server API can create and run jobs, potentially leading to remote code execution capabilities on the server and connected nodes if not properly secured.

In addition to Nomad, the threat actors are also misusing Consul, a HashiCorp tool designed to secure network connectivity between services in various environments. By hijacking the health check service within Consul, the attackers can execute malicious commands and download and run crypto-mining payloads.

Furthermore, the attackers are exploiting vulnerabilities such as CVE-2020-14144 in Gitea and misconfigured versions of Docker Engine API to launch crypto-miner images within containers.

See also  Crypto firms among top targets of audio and video deepfake attacks

To protect against such attacks, Wiz recommends implementing the following best practices for DevOps tools:

  • Nomad: Implement ACLs and other security features as outlined in the official documentation’s Security Model section.
  • Gitea: Keep public instances up to date to prevent exploitation of RCE vulnerabilities, and avoid enabling git hooks or leaving installations unlocked unless necessary.
  • Consul: Activate security features detailed in the Secure Consul section of the official documentation, including disabling script checks and restricting the HTTP API to bind only to "localhost" where feasible.
  • Docker API: Refrain from binding the Docker API to 0.0.0.0 and avoid exposing the API to the internet.

    By following these best practices and ensuring that DevOps tools are properly configured and secured, organizations can mitigate the risk of falling victim to attacks like those orchestrated by the JINX-0132 threat group. Stay vigilant, stay secure.

Campaign Cryptojacking DevOps including Nomad Servers Targets
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

JD.com targets Stablecoin licences to cut cross-border payment costs The Block

June 20, 2025

North Korean Hackers Deploy Python-Based Trojan Targeting Crypto

June 20, 2025

Israeli Hacktivists Steal and Burn $90m+ from Iranian Crypo Biz

June 19, 2025

Gemini accuses CFTC of unfair legal campaign in formal complaint

June 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

TaskOn and Boinkers Join Forces to Fuel Web3 Adoption Through Gaming

May 24, 2025

Multiple Network Teams Up With Unmarshal AI to Revolutionize Blockchain Data Across 55+ Chains

February 27, 2025

FTX creditors begin receiving $1.2 billion in payouts with interest on Kraken

February 19, 2025
Price Chart


Explore insights on crypto, blockchain, taxes, and security. Stay informed with expert guides, tips, and the latest trends to navigate the digital asset world confidently


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Arizona revives bid for seized crypto reserve fund through House Bill 2324

June 20, 2025

Jupiter halts governance voting to tackle burnout and refocus on innovation

June 20, 2025

Visa Taps Yellow Card for Stablecoin Payments Push Across 20 African Nations

June 20, 2025
Get Informed

Subscribe to Updates

Get the latest creative news From BuyCryptoNews directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2025 BuyCryptoNews - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.