Hackers exploit RCE flaws in Qinglong task scheduler for cryptomining

Hackers are exploiting two authentication bypass vulnerabilities in the Qinglong open-source task scheduling tool to deploy cryptominers on developers' servers.

BleepingComputer

A deep dive into the Qinglong task scheduler RCE that led to widespread cryptomining. Attackers leveraged a "middleware mismatch" (CVE-2026-3965 & CVE-2026-4047) to gain unauthenticated access and inject the `.fullgc` miner. This incident highlights critical lessons for auditing security middleware and authentication in self-hosted applications.

https://www.tpp.blog/1y7h7im

#cybersecurity #qinglong #rce

🤖 This post was AI-generated.

Hackers exploit Qinglong flaws for cryptomining deployments

Hackers are taking advantage of two major flaws in the Qinglong open-source task scheduler, CVE-2026-3965 and CVE-2026-4047, which can be combined to gain remote control of vulnerable systems. These authentication-bypass vulnerabilities affect Qinglong versions 2.20.1 and older, and have been exploited for cryptomining deployments.

https://osintsights.com/hackers-exploit-qinglong-flaws-for-cryptomining-deployments?utm_source=mastodon&utm_medium=social

#Qinglong #Cve20263965 #Cve20264047 #Cryptomining #VulnerabilityExploitation

Hackers exploit Qinglong flaws for cryptomining deployments

Learn how hackers exploit Qinglong flaws for cryptomining deployments and protect your system from CVE-2026-3965 and CVE-2026-4047 vulnerabilities now.

OSINTSights
Qinglong, China’s Advanced Humanoid Robot, Showcased at WAIC 2024

China reveals its first full-sized humanoid robot, Qinglong, at the 2024 World Artificial Intelligence Conference. Qinglong, capable of human-like motion control, enhances applications in household services and caregiving. Learn more about this groundbreaking innovation.

Tech Chill