QINGLONG TASK SCHEDULER UNDER ATTACK FOR CRYPTOMINING
■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
Hackers are actively exploiting authentication bypass vulnerabilities in Qinglong, an open-source task scheduling tool, to deploy cryptominers on developer servers. The attacks target two separate RCE flaws in the platform.
■ MORE FROM THE SECURITY DESK
Cybercriminals have transformed DDoS attacks into a polished, commercialized service complete with pricing tiers, customer support, and reseller programs. The DDoS-as-a-Service market has evolved from basic tools into sophisticated attack platforms.
Microsoft faced backlash after threatening a security researcher with criminal investigation, reigniting debate over software vulnerability disclosure practices and corporate responsibility.
Google is deploying Device Bound Session Credentials (DBSC) to all Chrome users, a security feature designed to prevent account takeovers by protecting session cookies from theft.
Dutch authorities have dismantled a major botnet comprising 17 million infected devices and seized over 200 servers hosting the operation at a local provider.