Country visual unavailable
No information
Kong disclosed that an unauthorized actor compromised its software publication workflow and published a malicious Kong Ingress Controller 3.4.0 Docker image containing a cryptocurrency miner. Legitimate Docker tags pointed to the unauthorized image, which was downloaded 202 times before Kong removed it and rebuilt the release. The compromise therefore propagated malicious code through a legitimate software-distribution channel, constituting a directly evidenced software supply-chain integrity impact.
Estimated severity
70 / 100
Source reliability
92 / 100
Approximate Date
24/12/2024
Targeted Company
KONG
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
Country visual unavailable
No information
No other affected countries reported
Target country
No information
Affected countries
No information
Impacted regions
No information
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
No information
Please rotate your phone