Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

CLARITY Act Push Gains Momentum as Lawmakers Race to Lock in US Crypto Rules

June 8, 2026

Cardano Crash Exposes ADA’s Deeper Problem, Says Longtime Bull

June 8, 2026

PR Newswire Signs Affiliate Membership with PRCAI to Strengthen India’s Communications Ecosystem

June 8, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Flaw in Apache ActiveMQ Exposes Linux Systems to Kinsing Malware
Flaw in Apache ActiveMQ Exposes Linux Systems to Kinsing Malware
Security and Privacy

Flaw in Apache ActiveMQ Exposes Linux Systems to Kinsing Malware

November 22, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A critical vulnerability in Apache ActiveMQ, identified as CVE-2023-46604, has been exposed, revealing an active exploitation scenario by the notorious Kinsing malware. 

According to an advisory published by Trend Micro on Monday, the discovery underscores the implications for Linux systems, as the vulnerability allows for remote code execution (RCE) due to inadequate validation of throwable class types in OpenWire commands. 

Apache ActiveMQ, a Java-based open source protocol, is widely used for message-oriented middleware, facilitating seamless communication between diverse applications.

Kinsing, a potent threat specifically targeting Linux-based systems, capitalizes on web application vulnerabilities and misconfigured container environments to infiltrate servers and swiftly propagate across networks. 

Reports of active exploitation of CVE-2023-46604 surfaced in November, with threat actors employing exploits such as Metasploit and Nuclei. Despite the severity of the vulnerability (CVSS 9.8), detection remains relatively low. 

“The danger with this CVE is that Apache ActiveMQ is widely used, and because it can communicate across multiple protocols (such as MQTT), it is also widely used in non-IT environments to interface to IoT/OT/ICS devices,” explained John Gallagher, vice president of Viakoo Labs at Viakoo.

“Many IoT devices have powerful processing capabilities and lack patching policies, making [crypto]mining an ideal activity for them.”

The Kinsing exploit utilizes the ProcessBuilder method, leading to the download and execution of cryptocurrency miners and malware on compromised systems. Notably, the malware actively seeks and eliminates competing cryptocurrency miners.

The threat actors orchestrating Kinsing exploit not only CVE-2023-46604 but also other high-profile vulnerabilities like CVE-2023-4911 (Looney Tunables).

Read more on Kinsing: Docker Users Targeted with Crypto Malware Via Exposed APIs

Trend Micro urged users to promptly upgrade to mitigate the risks associated with this vulnerability. The patch for CVE-2023-46604 addresses the root cause by introducing the “validateIsThrowable” method in the “BaseDataStreamMarshall” class.

See also  Sophisticated Email Attacks Target Cryptocurrency Wallets

“To guard against this [threat], organizations should prioritize patching and remediation, especially for all external-facing exposure and those with higher-value assets,” said Ken Dunham, director of cyber threat at Qualys.

“Additionally, precautions such as extensive monitoring and logging reviews with workarounds where they apply are recommended to counter known TTPs for brute-force and known attacks until the risk of exploitation is fully remediated.”

Source link

ActiveMQ Apache Exposes Flaw Kinsing Linux Malware Systems
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Cardano Crash Exposes ADA’s Deeper Problem, Says Longtime Bull

June 8, 2026

3D Systems Announces Pricing of $50 Million Upsized Public Offering

June 4, 2026

Infosecurity Europe: AI-Powered Cybercrime Tools Surge on Dark Web

June 3, 2026

Stake DAO Freezes Arbitrum vsdCRV Markets After Attacker Mints 5.4T Synthetic Tokens

May 29, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Coinbase makes history with S&P 500 induction, reinforcing crypto’s arrival in mainstream finance

May 13, 2025

XRP Price Could Be Soon The Next One To Rally – Here’s Why

December 22, 2023

Bitcoin Price Nosedives Below Support As Bears Target $25K

June 6, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

CLARITY Act Push Gains Momentum as Lawmakers Race to Lock in US Crypto Rules

June 8, 2026

Cardano Crash Exposes ADA’s Deeper Problem, Says Longtime Bull

June 8, 2026

PR Newswire Signs Affiliate Membership with PRCAI to Strengthen India’s Communications Ecosystem

June 8, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$63,213.001.41%
  • ethereumEthereum(ETH)$1,670.082.41%
  • tetherTether(USDT)$1.00-0.03%
  • binancecoinBNB(BNB)$598.271.11%
  • usd-coinUSDC(USDC)$1.000.00%
  • rippleXRP(XRP)$1.150.92%
  • solanaSolana(SOL)$66.061.94%
  • tronTRON(TRX)$0.326179-0.89%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.00%
  • HyperliquidHyperliquid(HYPE)$61.424.27%