Home / Companies / Sysdig / Blog / Post Details
Content Deep Dive

Threat news: Tsunami malware mutated. Now targeting Jenkins and Weblogic services

Blog post from Sysdig

Post Details
Company
Date Published
Author
Alberto Pellitteri
Word Count
1,246
Company Posts That Month
8
Language
English
Hacker News Points
-
Post removed?
No
Summary

The Tsunami malware, a backdoor first identified years ago, has resurfaced with new capabilities targeting Jenkins and Weblogic services within Kubernetes clusters, exploiting vulnerabilities and misconfigurations to gain control over infected systems. Once a system is compromised, attackers can execute shell commands, download files, perform DDoS attacks, and even run cryptocurrency miners, leveraging IRC servers for command and control communication. Despite past patches for vulnerabilities like CVE-2020-14882, outdated container images remain susceptible, underscoring the importance of regular updates and vigilant security practices. To mitigate risks, Falco, a cloud-native runtime security tool, can detect suspicious activity by monitoring container environments and alerting users to potential threats. Keeping services updated and securing credentials are crucial steps in defending against such evolving threats.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Kubernetes 2 1,341 163 55 +34%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.