Campaign Drops Coinminer on Linux Boxes Using Old Elasticsearch Vulnerabilities

Campaign Drops Coinminer on Linux Boxes Using Old Elasticsearch Vulnerabilities

Actors pivot to other network devices from infected machines

57 Million Personal Info Records Leaked by Unprotected ElasticSearch Server

57 Million Personal Info Records Leaked by Unprotected ElasticSearch Server

The open database contained only US citizens' PII data

  • Security
  • By Catalin Cimpanu
  • December 3rd, 2015
Elasticsearch Servers Targeted by Linux-Based Botnet Operators

Elasticsearch Servers Targeted by Linux-Based Botnet Operators

30+ bots detected over a 3-month honeypot experiment

Administrators Continue to Fail in Securing Databases by Using Proper Configs

Administrators Continue to Fail in Securing Databases by Using Proper Configs

Redis, MongoDB, ElasticSearch, and Memcached servers are not properly configured by their administrators

Honeypot Records 8,000 Attacks Exploiting RCE Flaw in Elasticsearch

Honeypot Records 8,000 Attacks Exploiting RCE Flaw in Elasticsearch

Most of the assaults originate from machines in China

Exploit Code Published for Elasticsearch Remote Code Execution Flaw

Exploit Code Published for Elasticsearch Remote Code Execution Flaw

There is indication that the glitch is exploited in the wild