:

QINGLONG TASK SCHEDULER UNDER ATTACK FOR CRYPTOMINING

SECURITY DESK1 MIN READ
THU, MAY 21, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Hackers are actively exploiting authentication bypass vulnerabilities in Qinglong, an open-source task scheduling tool, to deploy cryptominers on developer servers. The attacks target two separate RCE flaws in the platform.

Qinglong, a popular task scheduler used by developers for automation, contains critical vulnerabilities allowing unauthenticated remote code execution. Threat actors are leveraging these flaws to gain server access and install cryptocurrency mining malware. The authentication bypass vulnerabilities enable attackers to execute arbitrary commands without valid credentials. Once compromised, affected servers become part of cryptomining botnets, consuming computational resources and increasing operational costs. Qinglong users should immediately update to the latest patched version. Organizations running the tool should audit server logs for suspicious activity and monitor CPU usage for signs of unauthorized mining operations. The vulnerability underscores ongoing risks in open-source infrastructure tools. Developers relying on Qinglong for production workloads should prioritize patching and implement network segmentation to limit exposure.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A woman has alleged that her stepfather used Grok, an AI image generation tool, to transform a childhood photograph into explicit sexual imagery. The claim highlights growing concerns about AI systems being weaponized to produce child sexual abuse material (CSAM).

2H AGOAI Desk

Ukrainian authorities have dismantled 94 fraudulent call centers operating across the country. The operation seized millions in cash from operations targeting victims with investment scams and bank account theft schemes.

6H AGOAI Desk

With AI platforms becoming prime targets for hackers, knowing how to detect unauthorized access to your accounts is essential. Here's what to watch for.

6H AGOAI Desk

Researchers have identified Evooo1Bot, a new Mirai-based Linux botnet that targets internet-facing gateway devices and converts them into SOCKS5 traffic relay nodes. The modular malware represents an evolution in how attackers compromise network infrastructure.

9H AGODev Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.