Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Gaming
  • Legal
    • Legal and Regulatory
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
What's Hot

Explosive Class Action Alleges False Advertising and Market Manipulation in Crypto AI Project

April 23, 2026

Could Ripple XRP Power Cross-Border Payments? Russia’s Early Tests Suggest Potential

April 23, 2026

More than 90% of Web3 games failed after $15 billion boom as gamers never showed up: Caladan

April 23, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    Pantera Capital Urges Satsuma To Dump All Bitcoin As Shares Collapse 99%

    April 23, 2026

    Bitcoin funding hits 2023 lows – Why $80K is BTC’s next big test

    April 23, 2026

    Bitcoin Price Jumps Above $78K as Strong Demand Returns: Breakout Ahead?

    April 23, 2026

    Billionaire Tim Draper Says He Has ‘Reason To Believe’ Bitcoin Will Explode 230% – Here’s His Timeline

    April 23, 2026

    Bitmine Stakes 61,232 ETH Worth $142M

    April 22, 2026

    Ethereum Targets Lower Range As Resistance Zone Comes Into Play

    April 22, 2026

    Ethereum Price Rises, But On-Chain Data Signals Weak Demand —What’s Next for ETH?

    April 21, 2026

    Ethereum’s Next Rally May Have Started: But No One Is Talking About It

    April 21, 2026

    Could Ripple XRP Power Cross-Border Payments? Russia’s Early Tests Suggest Potential

    April 23, 2026

    Crypto Billionaire Justin Sun Files Lawsuit Against Trump-Linked World Liberty Financial Over ‘Wrongfully’ Frozen Tokens

    April 23, 2026

    Ethereum Price Rejected Above $2,400, Upside Momentum Starts To Fade

    April 23, 2026

    CEO Calls CLARITY Act ‘Horrible Bill,’ Warns Of Prolonged Crypto Bear Market Ahead

    April 23, 2026

    Meme Coin Market Faces Imbalance as Supply Rises, Demand Falls

    April 4, 2026

    Crypto Interest Rising Toward Meme Coin Sector

    January 9, 2026

    Memes Market Cap Adds $10B in Days: Fresh Capital or Dead-Cat-Bounce?

    January 5, 2026

    Meme Coin Market Surges Past $45B as Shiba Inu, PEPE, BONK Stage 54% Price Pump

    January 4, 2026

    Explosive Class Action Alleges False Advertising and Market Manipulation in Crypto AI Project

    April 23, 2026

    Could Ripple XRP Power Cross-Border Payments? Russia’s Early Tests Suggest Potential

    April 23, 2026

    More than 90% of Web3 games failed after $15 billion boom as gamers never showed up: Caladan

    April 23, 2026

    ZetaChain Onboards Kimi and Alibaba Qwen as AI Models Go Cross-Chain

    April 23, 2026
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    ZetaChain Onboards Kimi and Alibaba Qwen as AI Models Go Cross-Chain

    April 23, 2026

    Monthly Active Addresses Explode – Analyzing the Surge in Layer-1 and Layer-2 Network Utility

    April 23, 2026

    AI agents that trade crypto autonomously are the next big shift in blockchain

    April 23, 2026

    USDT Now Live on Solana, Plasma, and Ethereum With 1:1 USD Onramps and Offramps: Privy and Ramp

    April 23, 2026

    How crypto futures markets are feeding ‘scam coin’ insider pump and dumps

    April 22, 2026

    North Korean Blamed for $290m KelpDAO Crypto Heist

    April 21, 2026

    Chainalysis Flags Critical Blind Spot in DeFi Security as $292M Exploit Bypasses Burn Verification

    April 21, 2026

    Ripple’s Schwartz Flags DeFi Bridge Trade-Offs After KelpDAO Incident

    April 21, 2026

    Explosive Class Action Alleges False Advertising and Market Manipulation in Crypto AI Project

    April 23, 2026

    Could Ripple XRP Power Cross-Border Payments? Russia’s Early Tests Suggest Potential

    April 23, 2026

    More than 90% of Web3 games failed after $15 billion boom as gamers never showed up: Caladan

    April 23, 2026

    ZetaChain Onboards Kimi and Alibaba Qwen as AI Models Go Cross-Chain

    April 23, 2026
  • Web 3
    1. Gaming
    2. View All

    More than 90% of Web3 games failed after $15 billion boom as gamers never showed up: Caladan

    April 23, 2026

    Carbon 2.0: How dMRV Is Turning Carbon Credits Into Data-Driven Assets

    April 23, 2026

    UXLINK Taps ANOME Protocol to Redefine Web3 Gaming, SocialFi, and NFTFi

    April 23, 2026

    ‘Axie Infinity’ Gaming Network Ronin Sets Date for Ethereum Layer-2 Migration

    April 23, 2026

    Explosive Class Action Alleges False Advertising and Market Manipulation in Crypto AI Project

    April 23, 2026

    Could Ripple XRP Power Cross-Border Payments? Russia’s Early Tests Suggest Potential

    April 23, 2026

    More than 90% of Web3 games failed after $15 billion boom as gamers never showed up: Caladan

    April 23, 2026

    ZetaChain Onboards Kimi and Alibaba Qwen as AI Models Go Cross-Chain

    April 23, 2026
  • Legal
    1. Legal and Regulatory
    2. Adoption
    3. View All

    Explosive Class Action Alleges False Advertising and Market Manipulation in Crypto AI Project

    April 23, 2026

    US admiral who blasted crypto is now running a Bitcoin node for America’s security

    April 23, 2026

    Mississippi Law School Requires AI Training as Courts Grapple With the Tech

    April 23, 2026

    Mob boss John Gotti’s grandson is headed to prison for a $1.1 million Covid fraud and crypto scheme

    April 23, 2026

    Oil tanker attacked after falling for crypto scam granting fake Strait of Hormuz safe passage

    April 21, 2026

    Six years after “DeFi Summer” is the sun already setting on the decentralized finance revolution?

    April 20, 2026

    Bitcoin network activity just hit an 8-year low — has Wall Street replaced retail in the market?

    April 19, 2026

    Charles Schwab is bringing uninsured Bitcoin to 39M clients

    April 19, 2026

    Explosive Class Action Alleges False Advertising and Market Manipulation in Crypto AI Project

    April 23, 2026

    Could Ripple XRP Power Cross-Border Payments? Russia’s Early Tests Suggest Potential

    April 23, 2026

    More than 90% of Web3 games failed after $15 billion boom as gamers never showed up: Caladan

    April 23, 2026

    ZetaChain Onboards Kimi and Alibaba Qwen as AI Models Go Cross-Chain

    April 23, 2026
  • Analysis

    ZEC Price Prediction: Zcash Retests Key Level

    April 23, 2026

    Monero Price Analysis: XMR Presses $400 Resistance

    April 23, 2026

    Bitcoin’s uptrend towards $80,000 is increasingly attracting bears

    April 23, 2026

    Traders Bet on $100K Bitcoin Price as Breakout Rally Erases Weeks of Sideways Pain

    April 23, 2026

    Inside the fight to turn prediction apps into nonstop leverage casinos

    April 23, 2026
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What’s on the Ethereum Roadmap: Glamsterdam, Hegota and Beyond

    March 30, 2026

    What Is Bluesky? The Decentralized Social Media Rival to Elon Musk’s X

    March 27, 2026

    What Is Strategy (MSTR)? The Bitcoin Treasury Company

    February 21, 2026

    What Are Prediction Markets? How Polymarket, Kalshi and Myriad Work

    February 13, 2026

    Over 80% of Bitcoin ETF assets hit Coinbase custody choke point with $74B at risk

    April 13, 2026

    FTX begins $2.2B payout. Can Bitcoin absorb another liquidity test?

    March 31, 2026

    BlinkEx investment platform infrastructure – matching, risk controls, reliability

    March 21, 2026

    Over $2B in “lost” Bitcoin to hit markets this month creating sell pressure within fragile $67k–$74k range

    March 20, 2026

    Explosive Class Action Alleges False Advertising and Market Manipulation in Crypto AI Project

    April 23, 2026

    Could Ripple XRP Power Cross-Border Payments? Russia’s Early Tests Suggest Potential

    April 23, 2026

    More than 90% of Web3 games failed after $15 billion boom as gamers never showed up: Caladan

    April 23, 2026

    ZetaChain Onboards Kimi and Alibaba Qwen as AI Models Go Cross-Chain

    April 23, 2026
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
Home»Security and Privacy»Cryptojacking Campaign Targets DevOps Servers Including Nomad
Cryptojacking Campaign Targets DevOps Servers Including Nomad
Security and Privacy

Cryptojacking Campaign Targets DevOps Servers Including Nomad

September 10, 2025No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Researchers claim to have discovered the first case of threat actors using misconfigured HashiCorp Nomad deployments as an attack vector.

The popular DevOps platform, which enables firms to deploy and manage containers and non-containerized applications, is being targeted alongside other infrastructure, including Gitea, Consul and Docker API, according to cloud security provider Wiz.

The threat group in question, named by Wiz as JINX-0132, is exploiting misconfigurations and vulnerabilities in these DevOps tools for cryptojacking, the report claimed.

Based on Wiz data, a quarter (25%) of all cloud environments run at least one of the targeted technologies. Of the environments using these tools, 5% expose them directly to the internet, and among these deployments, 30% are apparently misconfigured.

Read more on cryptojacking: Malicious Microsoft VS Code Extensions Used in Cryptojacking Campaign

JINX-0132 attackers are taking advantage of Nomad’s job queue feature, which allows users to submit tasks for execution by nodes registered with the Nomad server.

“By default – and critically, if not reconfigured by administrators – any user with access to the Nomad server API can create and run these jobs. This default configuration effectively means that unrestricted access to the server API can be tantamount to remote code execution (RCE) capabilities on the server itself and all connected nodes,” Wiz said.

In this way, the threat actors create multiple new jobs on compromised hosts to download the XMRig miner directly from its public GitHub repository, unpack the archive, grant execution permissions and execute.

They are also abusing another HashiCorp tool, Consul, which is designed to help DevOps teams secure network connectivity between services and across on-premises and multi-cloud environments and runtimes.

See also  Cyrpto Me0wing, Not a Cute Kitty of the Internet

Specifically, they are hijacking the health check service to execute bash commands and download and run XMRig payloads.

“Unless ACLs [access control lists] have been configured or security features provided by HashiCorp have been enabled, any user with remote access to the server can register services and health checks and abuse this functionality for remote code execution,” Wiz warned.

JINX-0132 is also exploiting CVE-2020-14144 in older versions of open source GitHub alternative Gitea, as well as misconfigured versions of Docker Engine API. In the latter case, they have been able to create containers that launch crypto-miner images, according to the report.

Best Practices for DevOps

To avoid becoming another JINX-0132 victim, Wiz urged customers of the aforementioned DevOps tools to do the following:

  • Nomad: Implement the ACLs and other security features listed in the Security Model section of the official documentation
  • Gitea: Keep public Gitea instances up to date to prevent exploitation of RCE vulnerabilities, and don’t enable git hooks or leave the installation unlocked unless absolutely necessary
  • Consul: Switch on the security features listed in the Secure Consul section of the official documentation, including disabling script checks, and restricting the HTTP API to bind only to “localhost” where possible
  • Docker API: Do not bind the Docker API to 0.0.0.0, and don’t expose the API to the internet
Campaign Cryptojacking DevOps Including Nomad Servers Targets
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Kalshi flags more insider trading cases, including politician who appeared on FBoy Island

April 23, 2026

Ethereum Targets Lower Range As Resistance Zone Comes Into Play

April 22, 2026

How crypto futures markets are feeding ‘scam coin’ insider pump and dumps

April 22, 2026

North Korean Blamed for $290m KelpDAO Crypto Heist

April 21, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Bhutan Sells Another $6.7M in Bitcoin

February 13, 2026

BitMart Confirms $150M Crypto Theft

October 24, 2025

Stay ahead with the latest crypto news, market updates, blockchain insights, and trends. Your trusted source for everything happening in the digital asset world.


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Explosive Class Action Alleges False Advertising and Market Manipulation in Crypto AI Project

April 23, 2026

Could Ripple XRP Power Cross-Border Payments? Russia’s Early Tests Suggest Potential

April 23, 2026

More than 90% of Web3 games failed after $15 billion boom as gamers never showed up: Caladan

April 23, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Free.cc directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2026 free.cc - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.