<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cryptomining on CuraSec</title><link>https://curasec.metacog.co.kr/tags/cryptomining/</link><description>Recent content in Cryptomining on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 27 Aug 2026 21:01:55 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/cryptomining/index.xml" rel="self" type="application/rss+xml"/><item><title>Microsoft TI: LiteLLM gateways actively exploited for cred theft and cryptomining</title><link>https://curasec.metacog.co.kr/insights/2026-08-27-when-ai-infrastructure-becomes-the-target-securing-gateways/</link><pubDate>Thu, 27 Aug 2026 21:01:55 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-27-when-ai-infrastructure-becomes-the-target-securing-gateways/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Microsoft Threat Intelligence documents active exploitation of exposed LiteLLM gateways leading to credential theft and persistence — no KEV or PoC signal, but if you run LiteLLM or similar AI proxies, audit internet exposure, rotate API keys, and verify no unauthorized processes are running on those hosts.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active attack chain with detectable post-exploitation stages (credential harvesting, persistence, cryptomining) reported by Microsoft TI — pull the blog post for IOCs, then hunt for anomalous processes and outbound connections on any hosts running AI gateway software since the publication date.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> AI workloads are now an established attack surface for credential theft and resource abuse; this quarter, ensure AI infrastructure (gateways, API proxies, GPU hosts) is included in your hardening and access-review scope alongside traditional edge assets.&lt;/li>
&lt;/ul></description></item><item><title>macOS Screen Sharing auth bypass exploited to drop Monero miner</title><link>https://curasec.metacog.co.kr/insights/2026-08-15-hackers-exploit-macos-screen-sharing-flaw-to-deploy-monero-m/</link><pubDate>Sat, 15 Aug 2026 11:32:14 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-15-hackers-exploit-macos-screen-sharing-flaw-to-deploy-monero-m/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Active exploitation with public PoC — audit your macOS fleet for Screen Sharing (VNC) exposure and apply Apple&amp;rsquo;s patch immediately; disable Screen Sharing on hosts where it isn&amp;rsquo;t required.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Hunt for unexpected xmrig or Monero miner processes on macOS endpoints and check for anomalous outbound connections to mining pools since the PoC went public.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Active cryptomining campaign on macOS is unlikely to require board-level action, but confirms macOS is not a safe-harbor — useful context for endpoint policy discussions.&lt;/li>
&lt;/ul></description></item></channel></rss>