Close Menu
    What's Hot

    Baltic Sea Darts Open: Luke Woodhouse wins again for first European Tour title in victory over Ryan Joyce | Darts News

    Morgan Rogers: Arsenal target Aston Villa forward – Paper Talk | Football News

    China Exports Surveillance – The New York Times

    Facebook X (Twitter) Instagram
    Trending
    • Baltic Sea Darts Open: Luke Woodhouse wins again for first European Tour title in victory over Ryan Joyce | Darts News
    • Morgan Rogers: Arsenal target Aston Villa forward – Paper Talk | Football News
    • China Exports Surveillance – The New York Times
    • Erin Brockovich takes aim at data center secrecy
    • U.S. Military Is Quietly Guiding Ships Through the Strait of Hormuz
    • Luis Enrique: ‘Lucky’ Arsenal goal gave PSG huge challenge
    • NHL odds, predictions: Hurricanes meet Golden Knights in 2026 Stanley Cup Final
    • How to watch Nvidia’s Computex keynote
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Exposed Training Open the Door for Crypto-Mining in Fortune 500 Cloud Environments

    adminBy adminFebruary 14, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Exposed Training Open the Door for Crypto-Mining in Fortune 500 Cloud Environments
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Hacker NewsFeb 11, 2026Identity Security / Threat Exposure

    Exposed Training Open the Door for Crypto-Mining in Fortune 500 Cloud Environments

    Intentionally vulnerable training applications are widely used for security education, internal testing, and product demonstrations. Tools such as OWASP Juice Shop, DVWA, Hackazon, and bWAPP are designed to be insecure by default, making them useful for learning how common attack techniques work in controlled environments.

    The issue is not the applications themselves, but how they are often deployed and maintained in real-world cloud environments.

    Pentera Labs examined how training and demo applications are being used across cloud infrastructures and identified a recurring pattern: applications intended for isolated lab use were frequently found exposed to the public internet, running inside active cloud accounts, and connected to cloud identities with broader access than required.

    Deployment Patterns Observed in the Research

    Pentera Labs research found that these applications were often deployed with default configurations, minimal isolation, and overly permissive cloud roles. The investigation uncovered that many of these exposed training environments were directly connected to active cloud identities and privileged roles, enabling attackers to move far beyond the vulnerable applications themselves and potentially into the customer’s broader cloud infrastructure.

    In these scenarios, a single exposed training application can act as an initial foothold. Once attackers are able to leverage connected cloud identities and privileged roles, they are no longer constrained to the original application or host. Instead, they may gain the ability to interact with other resources within the same cloud environment, significantly increasing the scope and potential impact of the compromise.

    As part of the investigation, Pentera Labs verified nearly 2,000 live, exposed training application instances, with close to 60% hosted on customer-managed infrastructure running on AWS, Azure, or GCP.

    Evidence of Active Exploitation

    The exposed training environments identified during the research were not simply misconfigured. Pentera Labs observed clear evidence that attackers were actively exploiting this exposure in the wild.

    Across the broader dataset of exposed training applications, approximately 20% of instances were found to contain artifacts deployed by malicious actors, including crypto-mining activity, webshells, and persistence mechanisms. These artifacts indicated prior compromise and ongoing abuse of exposed systems.

    The presence of active crypto-mining and persistence tooling demonstrates that exposed training applications are not only discoverable but are already being exploited at scale.

    Scope of Impact

    The exposed and exploited environments identified during the research were not limited to small or isolated test systems. Pentera Labs observed this deployment pattern across cloud environments associated with Fortune 500 organizations and leading cybersecurity vendors, including Palo Alto, F5, and Cloudflare.

    While individual environments varied, the underlying pattern remained consistent: a training or demo application deployed without sufficient isolation, left publicly accessible, and connected to privileged cloud identities.

    Why This Matters

    Training and demo environments are frequently treated as low-risk or temporary assets. As a result, they are often excluded from standard security monitoring, access reviews, and lifecycle management processes. Over time, these environments may remain exposed long after their original purpose has passed.

    The research shows that exploitation does not require zero-day vulnerabilities or advanced attack techniques. Default credentials, known weaknesses, and public exposure were sufficient to turn training applications into an entry point for broader cloud access.

    Labeling an environment as “training” or “test” does not reduce its risk. When exposed to the internet and connected to privileged cloud identities, these systems become part of the organization’s effective attack surface.

    Refer to the full Pentera Labs research blog & join a live webinar on Feb 12th to learn more about the methodology, discovery process, and real-world exploitation observed during this research. 

    This article was written by Noam Yaffe, Senior Security Researcher at Pentera Labs. For questions or discussion, contact labs@pentera.io

    Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

    Cloud CryptoMining door Environments Exposed Fortune Open training
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous Article“The TSA’s New $45 Fee to Fly Without ID is Illegal,” Says…
    Next Article Anker’s USB-C cable that lets you charge two gadgets at once is 20 percent off
    admin
    • Website

    Related Posts

    Baltic Sea Darts Open: Luke Woodhouse wins again for first European Tour title in victory over Ryan Joyce | Darts News

    May 31, 2026

    Claude Mythos exposed a hard truth: Your enterprise patching process is way too slow

    May 31, 2026

    French Open: Aryna Sabalenka and Naomi Osaka to meet in first women’s night-time slot at Roland-Garros since 2023 | Tennis News

    May 31, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Baltic Sea Darts Open: Luke Woodhouse wins again for first European Tour title in victory over Ryan Joyce | Darts News

    Morgan Rogers: Arsenal target Aston Villa forward – Paper Talk | Football News

    China Exports Surveillance – The New York Times

    Erin Brockovich takes aim at data center secrecy

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by