Hackers are scanning the internet for vulnerable Salt installs, Ghost blogging platform hacked
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-11651 +1 in the same advisory: …11652 | Authentication Bypass and Unauthenticated RCE in SaltStack Salt CVE-2020-11651 is a critical (CVSS 9.8) authentication bypass in SaltStack Salt's salt-master process: the ClearFuncs class fails to validate method calls, so a remote attacker can invoke privileged methods without authenticating. By sending crafted messages to the salt-master's network interface, an unauthenticated user can retrieve the master's root tokens/eauth credentials and use them to execute arbitrary commands on salt minions, yielding full remote code execution across the entire Salt deployment. Anyone running affected Salt versions before 2019.2.4 or 3000.x before 3000.2 — including Salt shipped in Debian, Ubuntu, openSUSE Leap, and VMware's Application Remote Collector — is exposed, especially masters reachable on their ZeroMQ ports. Exploitation is confirmed in the wild: the flaw is on CISA's KEV catalog, EPSS puts exploitation probability at 96.6%, attackers have been mass-scanning for vulnerable Salt installs, and breaches using this bug hit Cisco (six servers), LineageOS, Ghost, and DigiCert. Do: Upgrade salt-master to Salt 2019.2.4 or 3000.2 (or later), or apply the patched packages issued by Debian, Ubuntu, and openSUSE; VMware vROps customers should apply VMware's Application Remote Collector fix. Restrict access to the salt-master ZeroMQ ports (4505/4506) to trusted networks and review masters for signs of compromise, such as unexpected root tokens or unauthorized jobs run on minions. | 9.8 group max | 97% | KEV PoC ×2 |
| largetens of thousands of deployments (thousands of internet-exposed Salt masters, plus Salt bundled in Ubuntu/Debian/openSUSE and VMware ARC) |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | ghost.org | work.” The attackers had access to the Ghost(Pro) sites and Ghost.org billing services, but no personal and financial data were e |
Full article456 words · extracted from securityaffairs.com · click to collapse

Hackers are conducting a mass-scanning the Internet for vulnerable Salt installs that could allow them to hack the organizations, the last victim is the Ghost blogging platform.
Experts warn of hacking campaign that is targeting organization using the Salt platform for the management of their infrastructure, the last victim is the Ghost blogging platform.
The attackers exploited unpatched vulnerabilities to breach the Salt installations. Salt (aka SaltStack) is Python-based, open-source software for event-driven IT automation, remote task execution, and configuration management.
A few days ago, researchers from F-Secure disclosed a number of vulnerabilities in the “Salt” framework, including two issues that could be exploited by attackers to take over Salt installations.
The two flaws, tracked as CVE-2020-11651 and CVE-2020-11652, are a directory traversal issue and an authentication bypass vulnerability respectively. Chaining the issue, an attacker could bypass authentication and run arbitrary code on Salt master servers exposed online.
Administrators of Salt servers started reporting attacks exploiting the above vulnerabilities last week, threat actors used them to deliver backdoors and miners.
The same vulnerabilities in the Salt platform have been exploited during the weekend to hack the infrastructure of Lineageos.
A few hours later another security incident was reported by the media, ZDNet reported that the Node.js-based blogging platform Ghost suffered a similar incident. The attackers compromised the blogging platform to deploy a cryptocurrency miner, the intrusion took place on May 3, 2020.
“Around 1:30AM UTC on May 3rd, 2020 an attacker used a CVE in our saltstack master to gain access to our infrastructure (please see https://docs.saltstack.com/en/latest/topics/releases/3000.2.html for more information). This affects both Ghost(Pro) sites and Ghost.org billing services.” reads the statement published by Ghost Team.
“All traces of the crypto-mining virus were successfully eliminated yesterday, all systems remain stable, and we have not discovered any further concerns or issues on our network. The team is now working hard on remediation to clean and rebuild our entire network.”
The attackers had access to the Ghost(Pro) sites and Ghost.org billing services, but no personal and financial data were exposed as result of the intrusion.
The Ghost team took down its servers and addressed the flaws before resuming operations.
Experts believe that we will observe a spike in attacks against vulnerable Salt install exposed online in the next weeks. Threat actors could exploit the two vulnerabilities to install backdoors, miners, and ransomware in the compromised infrastructures.
ZDNet speculates the involvement of the operators of the infamous Kinsing botnet behind the attacks reported in the last hours.
Administrators should install the available security updates to protect their installs.
Please vote Security Affairs for European Cybersecurity Blogger Awards – VOTE FOR YOUR WINNERS
https://docs.google.com/forms/d/e/1FAIpQLSe8AkYMfAAwJ4JZzYRm8GfsJCDON8q83C9_wu5u10sNAt_CcA/viewform
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – Salt, hacking)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/102718/hacking/salt-hacking-campaign-ghost-hacked.html