Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • DeFi
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • Gaming
  • Legal
    • Taxes & Regulation
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Converter
What's Hot

Best Crypto Casino Review Websites for Bitcoin & No-KYC Gamblers in 2025

July 12, 2025

OpBNB Dominates in Blockchain Gaming UAWs, SKALE, RONIN, SEI, WAX & Other Ranked Top Performers

July 12, 2025

Trump crypto holdings edge higher as WLFI pushes for open trading

July 12, 2025
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Buy Crypto NewsBuy Crypto News
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    KULR Technology Increases Bitcoin Holdings To $101 Million

    July 11, 2025

    Analysts Predict Bitcoin to Hit $140K With Strong Momentum 

    July 11, 2025

    $687,220,000 in Bitcoin Shorts Liquidated in Just One Hour As BTC Explodes To $116,000

    July 11, 2025

    Bitcoin Hits New All Time High Of $113,900 As Adoption Accelerates

    July 11, 2025

    Ethereum Price Poised for $4,000 Rally

    July 11, 2025

    Breakout Above $2,800 Could Ignite Altseason

    July 11, 2025

    Ethereum: What’s standing between ETH and $3K? – Data suggests…

    July 11, 2025

    Crypto Analyst Says One Top-10 Altcoin’s Chart Looks ‘Disgustingly Good,’ Updates Outlook on Bitcoin and Ethereum

    July 11, 2025

    XRP Price Rallies 10%, Yet 2,000 Traders FOMO This AI Presale

    July 12, 2025

    Zero-Knowledge Proof Altcoin Lagrange (LA) Crashes Following Announcement of New Binance Listing

    July 11, 2025

    Hyperliquid to onboard 10M Phantom users – Will HYPE hit $120 now?

    July 11, 2025

    Bitcoin Uptrend Intact, But Binance Activity Warns Of Short-Term Pullback

    July 11, 2025

    Pepe, BMT, CAKE: Crypto Activity Heats Up

    March 18, 2025

    SHIB Burns Over Half a Billion Tokens, Price Surges Over 7%

    March 17, 2025

    DOGE Sees Massive User Growth: Active Addresses Up 400%

    March 15, 2025

    Shiba Inu (SHIB) Price Analysis: Bullish Hints, Bearish Trend

    March 15, 2025

    Best Crypto Casino Review Websites for Bitcoin & No-KYC Gamblers in 2025

    July 12, 2025

    OpBNB Dominates in Blockchain Gaming UAWs, SKALE, RONIN, SEI, WAX & Other Ranked Top Performers

    July 12, 2025

    Trump crypto holdings edge higher as WLFI pushes for open trading

    July 12, 2025

    Tornado Cash Judge Won’t Let One Case Be Mentioned in Roman Storm’s Trial: Here’s Why

    July 12, 2025
  • DeFi

    Opyn’s top minds defect to Coinbase in strategic shift toward onchain derivatives

    July 11, 2025

    SEI targets 55% rally as native USDC support sparks inverse H&S breakout

    July 11, 2025

    Robinhood launches ETH, SOL staking services for US users with $1 minimum

    July 11, 2025

    Corporate Bitcoin holdings hit $91B as Q2 sees record surge in adoption

    July 11, 2025

    Puff, puff, Pavel Durov? Snoop Dogg launches weed-themed NFT drop on Telegram

    July 10, 2025
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    OpBNB Dominates in Blockchain Gaming UAWs, SKALE, RONIN, SEI, WAX & Other Ranked Top Performers

    July 12, 2025

    Crypto-Stealing Malware Surges as Scammers Impersonate AI, Web3 Startups — Here’s the Catch

    July 11, 2025

    German State Bank Issues €100M Bond on Polygon – Is TradFi Finally Embracing Crypto?

    July 11, 2025

    Rewards Bunny Integrates with AIDEN to Revolutionize Web3 Engagement

    July 11, 2025

    Chinese industry group warns Web3 and DeFi high-return deals hide classic Ponzi engines

    July 11, 2025

    Scam targets dormant Bitcoin wallets with fake legal notice

    July 9, 2025

    North Korean Hackers Target Crypto Firms with Novel macOS Malware

    July 3, 2025

    Crypto firms paid $2.7M monthly to North Korean workers

    July 3, 2025

    Best Crypto Casino Review Websites for Bitcoin & No-KYC Gamblers in 2025

    July 12, 2025

    OpBNB Dominates in Blockchain Gaming UAWs, SKALE, RONIN, SEI, WAX & Other Ranked Top Performers

    July 12, 2025

    Trump crypto holdings edge higher as WLFI pushes for open trading

    July 12, 2025

    Tornado Cash Judge Won’t Let One Case Be Mentioned in Roman Storm’s Trial: Here’s Why

    July 12, 2025
  • Web 3
    1. Web3 News
    2. Gaming
    3. View All

    Best Crypto Casino Review Websites for Bitcoin & No-KYC Gamblers in 2025

    July 12, 2025

    DNS Records Explained: A Beginner’s Guide to A, CNAME, TXT, and More

    July 11, 2025

    Top Trends Transforming the Sensor Fusion Market Landscape in 2025: Technological Advancements In Sensor Fusion Technology Transform Market Presence

    July 11, 2025

    .cgai — Protect Your Images from Theft and Public Misuse

    July 11, 2025

    Blazpay and Onmi AR Unite to Elevate Web3 Gaming Experience

    July 11, 2025

    ChatGPT vs X: Who Sees Crypto Narratives First?

    July 10, 2025

    Floki’s Valhalla Surpasses 100K Veras Minted Within Days of Launch

    July 10, 2025

    Gear Runner Integrates with Meta Arena to Deliver Gamified Real-World Activity and Move to Earn for GameFi Fans

    July 10, 2025

    Best Crypto Casino Review Websites for Bitcoin & No-KYC Gamblers in 2025

    July 12, 2025

    OpBNB Dominates in Blockchain Gaming UAWs, SKALE, RONIN, SEI, WAX & Other Ranked Top Performers

    July 12, 2025

    Trump crypto holdings edge higher as WLFI pushes for open trading

    July 12, 2025

    Tornado Cash Judge Won’t Let One Case Be Mentioned in Roman Storm’s Trial: Here’s Why

    July 12, 2025
  • Legal
    1. Taxes & Regulation
    2. Adoption
    3. View All

    Tornado Cash Judge Won’t Let One Case Be Mentioned in Roman Storm’s Trial: Here’s Why

    July 12, 2025

    6 Best Anonymous Crypto Wallets: Hide your Identity Legally

    July 11, 2025

    US Senate targets Bukele’s El Salvador, bill calls to sanction BTC strategy

    July 11, 2025

    Ethena rockets to $290 million in revenue, seeks SEC clarity on USDe

    July 11, 2025

    Bitcoin treasury adoption up 3x YoY, corporates accumulated 725,000 BTC so far

    July 11, 2025

    Circle’s USDC aims for China breakthrough with Ant Group alliance

    July 10, 2025

    SharpLink stock continues surging as treasury tops 200k Ethereum

    July 10, 2025

    Rex-Osprey spot Solana ETF doubles cumulative inflows to $41M on July 8

    July 10, 2025

    Best Crypto Casino Review Websites for Bitcoin & No-KYC Gamblers in 2025

    July 12, 2025

    OpBNB Dominates in Blockchain Gaming UAWs, SKALE, RONIN, SEI, WAX & Other Ranked Top Performers

    July 12, 2025

    Trump crypto holdings edge higher as WLFI pushes for open trading

    July 12, 2025

    Tornado Cash Judge Won’t Let One Case Be Mentioned in Roman Storm’s Trial: Here’s Why

    July 12, 2025
  • Analysis

    Omni Network Price Skyrockets 164%, Should You Buy Now?

    July 11, 2025

    Memecoin platform Pump.fun targets third-largest token sale in history

    July 11, 2025

    Anthony Scaramucci Says $180,000 Bitcoin Price Explosion Possible As BTC ‘Supremacy’ Creeps Up – Here’s His Timeline

    July 11, 2025

    Can Bulls Push DOGE Price to $0.22?

    July 11, 2025

    HyperLiquid breaks $8 billion daily trading volume pushing HYPE token near all-time highs

    July 10, 2025
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What Is Tokenization?

    July 11, 2025

    What Are Internet Capital Markets? Why Companies Are Launching Meme Coins

    June 16, 2025

    What is a Corporate Bitcoin Treasury? The Strategy Behind Companies Holding Crypto

    May 27, 2025

    What Are Tokenized Real-World Assets? Putting Physical Value On-Chain With RWAs

    May 19, 2025

    Trump crypto holdings edge higher as WLFI pushes for open trading

    July 12, 2025

    Coinbase partners with Perplexity for real-time crypto insights via AI

    July 11, 2025

    Rumble teams up with MoonPay to power crypto-fiat wallet integration

    July 11, 2025

    GMX suffers $42M hack, issues 10% bounty offer to hacker

    July 10, 2025

    Best Crypto Casino Review Websites for Bitcoin & No-KYC Gamblers in 2025

    July 12, 2025

    OpBNB Dominates in Blockchain Gaming UAWs, SKALE, RONIN, SEI, WAX & Other Ranked Top Performers

    July 12, 2025

    Trump crypto holdings edge higher as WLFI pushes for open trading

    July 12, 2025

    Tornado Cash Judge Won’t Let One Case Be Mentioned in Roman Storm’s Trial: Here’s Why

    July 12, 2025
  • Tools
    • Market Overview
    • Converter
Buy Crypto NewsBuy Crypto News
Home»Security and Privacy»Cryptojacking Campaign Targets DevOps Servers Including Nomad
Cryptojacking Campaign Targets DevOps Servers Including Nomad
Security and Privacy

Cryptojacking Campaign Targets DevOps Servers Including Nomad

June 3, 2025No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Researchers have recently uncovered a concerning trend in the cybersecurity landscape – threat actors are now targeting misconfigured HashiCorp Nomad deployments as an attack vector. HashiCorp Nomad is a popular DevOps platform that allows organizations to deploy and manage containers and non-containerized applications. Alongside Nomad, other infrastructure components such as Gitea, Consul, and Docker API are also being exploited by a threat group identified as JINX-0132 for cryptojacking activities.

According to a report by cloud security provider Wiz, a significant number of cloud environments, around 25%, are utilizing one or more of the targeted technologies. Shockingly, 5% of these environments expose these tools directly to the internet, and among these exposed deployments, 30% are found to be misconfigured. This creates a ripe opportunity for threat actors to exploit vulnerabilities and misconfigurations in these DevOps tools.

One of the key tactics employed by the JINX-0132 attackers involves leveraging Nomad’s job queue feature, which allows users to submit tasks for execution by nodes registered with the Nomad server. By default, any user with access to the Nomad server API can create and run jobs, potentially leading to remote code execution capabilities on the server and connected nodes if not properly secured.

In addition to Nomad, the threat actors are also misusing Consul, a HashiCorp tool designed to secure network connectivity between services in various environments. By hijacking the health check service within Consul, the attackers can execute malicious commands and download and run crypto-mining payloads.

Furthermore, the attackers are exploiting vulnerabilities such as CVE-2020-14144 in Gitea and misconfigured versions of Docker Engine API to launch crypto-miner images within containers.

See also  Proofpoint: We Block Up to Two Million Extortion Emails Daily

To protect against such attacks, Wiz recommends implementing the following best practices for DevOps tools:

  • Nomad: Implement ACLs and other security features as outlined in the official documentation’s Security Model section.
  • Gitea: Keep public instances up to date to prevent exploitation of RCE vulnerabilities, and avoid enabling git hooks or leaving installations unlocked unless necessary.
  • Consul: Activate security features detailed in the Secure Consul section of the official documentation, including disabling script checks and restricting the HTTP API to bind only to "localhost" where feasible.
  • Docker API: Refrain from binding the Docker API to 0.0.0.0 and avoid exposing the API to the internet.

    By following these best practices and ensuring that DevOps tools are properly configured and secured, organizations can mitigate the risk of falling victim to attacks like those orchestrated by the JINX-0132 threat group. Stay vigilant, stay secure.

Campaign Cryptojacking DevOps including Nomad Servers Targets
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

US Senate targets Bukele’s El Salvador, bill calls to sanction BTC strategy

July 11, 2025

SEI targets 55% rally as native USDC support sparks inverse H&S breakout

July 11, 2025

Memecoin platform Pump.fun targets third-largest token sale in history

July 11, 2025

Chinese industry group warns Web3 and DeFi high-return deals hide classic Ponzi engines

July 11, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Zoro and AgentsGPT Partner to Advance the Future of Tokenized AI Agents

July 6, 2025

SEC delays decisions on staking and in-kind redemptions for crypto ETFs to early June

April 15, 2025

Bitcoin (BTC) Gearing Up for Explosive Upside Move Amid Short-Term Bottoming Process, Says Swissblock

April 8, 2025
Price Chart


Explore insights on crypto, blockchain, taxes, and security. Stay informed with expert guides, tips, and the latest trends to navigate the digital asset world confidently


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Best Crypto Casino Review Websites for Bitcoin & No-KYC Gamblers in 2025

July 12, 2025

OpBNB Dominates in Blockchain Gaming UAWs, SKALE, RONIN, SEI, WAX & Other Ranked Top Performers

July 12, 2025

Trump crypto holdings edge higher as WLFI pushes for open trading

July 12, 2025
Get Informed

Subscribe to Updates

Get the latest creative news From BuyCryptoNews directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2025 BuyCryptoNews - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.