news
Breaking Cyber News From Cyberint
Breaking news feed of the latest cyber incidents, breaches, vulnerabilities, malware, ransomware and so much more.
- All Items
- Asia
- Handala
- Israel
- Business Services
- Jobinfo
- Data Encrypted For Impact
- Middle East
- Shelter Locations In Israel
- Cyber Fattah Team
- Saudi Arabia
- Saudi Games
- Retail
- Ben Horin & Alexandrovitz
- Zachary Levi And Sons - Construction
- Sivim It
- Government
- Kibbutz Almog
- Saban Brands Israel
- Manufacturing
- Mprest
- Digitalghost
- The Knesset
- Evil_Byte
- Nobitex
- Gonjeshke Darande
- South-Eastern Asia
- Sentap
- Kimia Farma
- exclusive
- Indonesia
- Chemicals And Allied Products
- Europe
- Northern Europe
- Sweden
- Scania
- Transportation
- Hensi
- Tbn Israel
- Media
- Weizmann Institute Of Science
- Education
- Israeli Air Force
- Resistancetrench
- Israel Antiquities Authority
- Dienet
- Cve-2025-24016
- Wazuh
- CVE-2025-24016
- North America
- United States
- Mirai
- Clayoxtymus1337
- Technology
- Epsilor Electric Fuel
- India
- Southern Asia
- Advanced Weapons And Equipment India
- Fin6
- More_Eggs
- Alex Lab
- Cryptocurrency
- Critical Infrastructures
- Zoldyck
- United Kingdom
- Edf Energy
- Ingress Tool Transfer
- Disable Or Modify Tools
- Sudo And Sudo Caching
- Spectrum
- Unix Shell
- Spearphishing Link
- Amos
- Credentials In Files
- Match Legitimate Name Or Location
- Telecommunications
- Israel Defense Forces
- Coca-Cola Europacific Partners
- Ghna
- Food And Kindred Products
- Automotive
- Locauto
- Italy
- Southern Europe
- Mercadona
- Whitecoat
- Spain
- Ups
- Healthcare
- Wow Health Solutions
- Cyprus Airways
- Rip_Real_World
- Netsupport Rat
- Tel Aviv University
- Illeak
- Desec0X
- Numero
- Cyberlock
- Unc6032
- Yashma
- Lucky_Gh0$T
- Chaos
- 303
- Deloitte
- Gucci
- Windows Credential Manager
- Password Managers
- Phishing
- File And Directory Discovery
- Obfuscated Files Or Information
- Input Capture
- Data From Local System
- Exfiltration Over C2 Channel
- User Execution
- System Information Discovery
- Drive-By Compromise
- Virtualization/Sandbox Evasion
- Credentials From Web Browsers
- Command And Scripting Interpreter
- Screen Capture
- Eddiestealer
- Credentials From Password Stores
- Australia
- Australia And New Zealand
- Superloop
- W_Tchdogs
- Docker
- Web Protocols
- Exploitation For Client Execution
- Change Default File Association
- Smb/Windows Admin Shares
- Deploy Container
- Escape To Host
- Lateral Tool Transfer
- Remote System Discovery
- External Remote Services
- Network Service Discovery
- Resource Hijacking
- Exploit Public-Facing Application
- Financial Theft
- Romania
- Bitdefender
- Cameleon
- Eastern Europe
- Venom Rat
- Vicioustrap
- Macao Special Administrative Region
- CVE-2023-20118
- Cisco
- Cve-2023-20118
- Eastern Asia
- Uat-6382
- Cve-2025-0944
- CVE-2025-0944
- Trimble
- Tetraloader
- Rundll32
- Silver Fox
- Dynamic-Link Library Injection
- Scheduled Task
- Powershell
- File Deletion
- Obfuscated Files Or Information: Encrypted Or Encoded Data
- Process Discovery
- Reflective Code Loading
- Malicious File
- Regsvr32
- Valleyrat
- China
- Masquerade Task Or Service
- Trickbot
- Warmcookie
- Qakbot
- Bumblebee
- Danabot
- Cetus
- Purehvnc
- Bytebreaker
- Telcel
- Mexico
- Viralgod
- Latin America And The Caribbean
- Peter Green Chilled
- Cellcom
-
May 28, 2025
Cryptojacking Campaign Targets Misconfigured Docker APIs
A new malware campaign has emerged, targeting misconfigured Docker API instances to create a cryptocurrency mining botnet focused on mining Dero currency. The threat actor exploits insecurely published Docker APIs to gain access to running containerized infrastructures, propagating the malware through a worm-like mechanism to infect other exposed Docker instances. The attack utilizes two main components: a propagation malware named 'nginx' that scans for vulnerable Docker APIs, and a 'cloud' Dero cryptocurrency miner. This campaign has been linked to previous cryptojacking operations and poses a significant risk to any network with insecure Docker APIs.