Microsoft Analysis Finds Misconfigured Kubeflow Workloads are a Security Risk
Summary
June 2020 by WEI LIEN DANG, CO-FOUNDER AND CHIEF STRATEGY OFFICER AT STACKROX A unique cyberattack campaign that targets Kubeflow, a machine-learning toolkit for Kubernetes, has affected large swathes of container clusters, according to Microsoft. This fact makes Kubernetes clusters that are used for ML tasks a perfect target for crypto mining campaigns, which was the aim of this attack. Closer inspection showed that the image runs a common open-source cryptojacking malware that mines the Monero virtual currency, known as XMRIG. WEI LIEN DANG, CO-FOUNDER AND CHIEF STRATEGY OFFICER AT STACKROX, A MOUNTAIN VIEW, CALIF.-BASED LEADER IN SECURITY FOR CONTAINERS AND KUBERNETES: "Cryptojacking is a still a popular attack. Organizations must take specific steps to ensure they’re protecting their container and Kubernetes assets across build, deploy, and runtime.