Blogging platform Ghost has been hacked . The attackers breached servers and installed a crypto-miner.

A serious hacking campaign has been taking place in recent hours, with dozens of companies already being compromised.
According to security researchers, in recent hours, hackers have been massively scanning the Internet for Salt, a type of software used to manage and automate servers within data centers, cloud server clusters, and corporate networks.
Attackers are exploiting two recently patched bugs to gain access to Salt servers and deploy a crypto-miner.
LineageOS has been hacked. Now the Ghost platform too.
Initially, hackers managed to breach the servers of LineageOS, a mobile operating system.
A second major hack occurred a few hours later. The second victim is Ghost, a Node.js -based blogging platform that was created and marketed as a simpler alternative to WordPress .
Ghost's development team said it detected a breach of its backend infrastructure systems at approximately 1:30 a.m.
Ghost developers stated that hackers used the CVE-2020-11651 (authentication bypass) and CVE-2020-11652 (directory traversal) vulnerabilities to take control of the main Salt server.

The blogging company said that while hackers had access to Ghost (Pro) sites and the Ghost.org billing services, they did not steal any financial information or credentials user.
Instead, Ghost said the hackers installed a crypto-miner.
“The mining attempt spiked CPUs and quickly overloaded most of our systems, which alerted us to the issue immediately,” the developers of the Ghost platform said.
As happened with LineageOS, the Ghost developers took down all the servers, fixed the systems, and notified about the situation after a few hours.
A security researcher said the attacks were likely carried out using an automated vulnerability scanner that detects unpatched Salt installations . The hackers then used the two bugs to install the malicious crypto-miner.
“Most likely, the hackers behind these scans don’t even know the type of companies they are currently breaching,” the researcher said. “We see such Salt servers at banks, web hosters, and Fortune 500 companies.”.
“Very soon ransomware gangs will start scanning for this bug, and we will see chaos.”
Some of these attacks have been reported in a GitHub thread. There are similar reports of an attacker planting a crypto-miner on compromised Salt systems. The botnet .
Saltstack ,the company behind the Salt software, released updates earlier this week to address the two vulnerabilities. Companies must either update their Salt servers or secure them behind a firewall. There are currently about 6,000 Salt servers exposed on the Internet.
