AI Sysadmin Reveals How Cryptojacking Campaign Evaded Scanners on Proxmox Hosts
An autonomous AI system administrator at Pulsed Media discovered a cryptojacking implant on twelve Proxmox VE hosts in September 2026, traced to an authentication bypass vulnerability designated CVE-2023-54391. The CVE's structured version data incorrectly marked Proxmox VE 7.4.3 as unaffected, causing all automated vulnerability scanners to miss the exposure entirely. Attackers exploited the flaw and then applied the vendor's own patch to the compromised hosts, making the systems appear secure while actively mining cryptocurrency. An LD_PRELOAD userland rootkit was also deployed to intercept system calls and hide malicious files from standard inspection tools. The incident highlights that flawed CVE version ranges can render automated compliance pipelines not just ineffective but actively misleading.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in