ZeroHour
Product

Hadoop

0 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

CVE-2026-57866: Apache Impala: Secrets Exfiltration via SSRF

Apache Impala CVE-2026-57866 lets authenticated users abuse ai_generate_text() to exfiltrate secrets from configured Hadoop credential providers via SSRF.

A server-side request forgery affects Apache Impala versions 4.4.0 through 4.5.1. Authenticated users with permission to execute the ai_generate_text() function can exfiltrate secrets provided by credential providers configured via hadoop.security.credential.provider.path in core-site.xml. The attacker must know the secret's key name, and Apache rates the issue 'important'.

New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy

Darktrace says the Chaos botnet now targets misconfigured cloud deployments like Hadoop and added a SOCKS proxy for traffic relaying.

Darktrace identified a new 64-bit ELF variant of the Chaos botnet targeting misconfigured cloud deployments, expanding beyond the malware's traditional focus on routers and edge devices. Captured in a deliberately misconfigured Hadoop honeypot instance, the intrusion began with an HTTP request creating an application that ran embedded shell commands to fetch the Chaos agent binary from pan.tenire[.]com, set chmod 777 permissions, execute it, and delete the artifact to reduce forensic traces. The restructured variant adds a SOCKS proxy feature letting compromised systems ferry attacker traffic, while removing SSH-based spread and router-exploit functions, suggesting monetization beyond crypto mining and DDoS-for-hire. Possible Chinese origin is suggested by language artifacts and infrastructure; the delivery domain was previously used in Silver Fox's Operation Silk Lure phishing campaign delivering ValleyRAT.

The Hacker News · 28d agoMalware1

Related CVEs

  • SSRF in Apache Impala lets authenticated users exfiltrate credential-provider secrets
    Apache Impala versions 4.4.x and 4.5.x contain a server-side request forgery (CWE-918) in the ai_generate_text() SQL function. An authenticated Impala user with permission to execute ai_generate_text() can trigger server-side requests that exfiltrate secrets supplied by the credential providers configured in the hadoop.security.credential.provider.path property of core-site.xml, provided the user already knows the secret's key name. Successful exploitation lets an attacker read sensitive credentials held by the Impala service, such as storage or cloud keys, potentially enabling follow-on access to the systems those credentials protect. Only deployments running Impala 4.4.x or 4.5.x that have credential providers configured and permit users to call the affected function are exposed. There is no CVSS score yet, no known public proof-of-concept, and no evidence of exploitation in the wild; the issue is not on the CISA KEV list.
    · Apache Impala 4.4.x and 4.5.x

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.