Exposed Training Applications Enable Crypto-Mining in Fortune 500 Cloud Environments
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Pentera Labs conducted research revealing that training and demo applications, which are intentionally insecure for educational purposes, are often deployed inappropriately within cloud environments. Nearly 2,000 instances were verified, with around 60% hosted on major platforms like AWS, Azure, or GCP. These applications were frequently found exposed to the public internet and connected to cloud identities with excessive permissions.
The investigation uncovered that many of these applications were deployed with default configurations and minimal isolation, allowing attackers to leverage them as footholds into broader cloud infrastructures. Evidence of active exploitation was found, with approximately 20% of instances containing artifacts from malicious actors, including crypto-mining activities and webshells.
This issue is particularly concerning as it affects not only small systems but also environments associated with Fortune 500 organizations and leading cybersecurity vendors like Palo Alto, F5, and Cloudflare. The consistent pattern of misconfiguration across these environments indicates a significant risk.
Why This Matters for Your Security
Organizations often underestimate the risks posed by training and demo environments, viewing them as temporary assets. This oversight can lead to prolonged exposure and vulnerability, especially when these systems are connected to privileged cloud identities. The research shows that attackers do not require advanced techniques; they can exploit known weaknesses and default credentials.
It is crucial for organizations to recognize that labeling an environment as “training” does not mitigate its risk. Exposed systems can be part of the organization’s attack surface, leading to potential data breaches and unauthorized access to sensitive resources.
Key Takeaways
- Regularly audit and review the configurations of training and demo applications to ensure they are not publicly accessible.
- Implement strict access controls and limit permissions for cloud identities connected to training environments.
- Monitor for signs of exploitation, such as unusual activity or unauthorized access attempts in cloud environments.
- Educate staff about the risks associated with exposed training applications and the importance of security hygiene.
- Establish a lifecycle management process to decommission training environments that are no longer in use.
Key Terms & Concepts
- Crypto-mining: In this article, crypto-mining refers to the process of using computer resources to validate cryptocurrency transactions, which can be exploited by attackers.
- Webshells: Webshells are malicious scripts that allow attackers to remotely control a compromised server or application.
- Pentera Labs: Pentera Labs is a security research organization that investigates vulnerabilities and threats in cloud environments.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.