HomeSecurityCloud workloads: A large percentage have been compromised by cryptojackers

Cloud workloads: A large percentage have been compromised by cryptojackers

Cloud platforms are very popular these days . More and more businesses are moving applications to public cloud platforms. However, a new study shows that these platforms are not very secure as they have many vulnerabilities that hackers could exploit to steal user data . According to the study, 28% of cloud workloads have been affected by cryptomining malware .Cloud

The study , conducted by security firm Palo Alto Networks and examining multiple platforms, found that human errorwas one of the top causes of sensitive data exposure. Such errors left data vulnerable to more than 34 million vulnerabilities in installed systems.

Out -of-date or misconfigured Apache servers, jQuery packages, and other applications carried 29.13 million vulnerabilities in Amazon EC2 cloud systems, 3.97 million vulnerabilities in Google Cloud Platform Compute Engine, and 1.72 million vulnerabilities in Microsoft's Azure Virtual Machine.

Misconfiguration was one of the most significant problems across the platforms examined. 65% of security issues were the result of misconfiguration.

Cloud workloads: A large percentage have been compromised by cryptojackers

IBM and Gartner have repeatedly highlighted this as an issue that needs to be addressed. It is estimated that by 2020, 80% of breaches in cloud platforms will be due to misconfiguration and mismanagement of credentials.

56% of workloads had at least one Remote Desktop Protocol (RDP) service exposed to the Internet, leaving thousands of cloud users vulnerable to attacksthat would give hackers remote access.

Researchers have discovered that many popular cloud platforms have vulnerabilities. What is worrying is that cryptominer malware has infiltrated the platforms, which indicates that cybercriminals are already exploiting these vulnerabilities.

Nearly a third of the workloads examined communicated with malicious cryptomining command-and-server domains, which were operated by the Rocke hacking group.

“Timely and consistent cloud system update and patching programs are an effective way to slow down such threats,” the research team said.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS