BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Exposed Cloud Training Apps Exploited by Attackers

Demo apps left exposed become silent cloud hijackers for Fortune 500 environments.

  • Security researchers found nearly 2,000 publicly exposed, intentionally vulnerable training apps in cloud environments, with 60% hosted on customer-managed infrastructure.
  • Approximately 20% of these exposed instances contained artifacts from active exploitation, including crypto-mining activity and webshells.
  • The pattern affected major organizations, including Fortune 500 companies and cybersecurity vendors like Palo Alto, F5, and Cloudflare, creating a foothold for broader cloud access.
  • Exploitation leveraged default credentials and known weaknesses, not advanced techniques, turning demo tools into significant security risks.

“Intentionally vulnerable training applications are widely used for security education, internal testing, and product demonstrations.” However, new research reveals these demo tools are often dangerously misconfigured in live cloud environments. A recent Pentera Labs research investigation identified a recurring and risky deployment pattern across major cloud platforms. Consequently, applications like OWASP Juice Shop or DVWA were frequently found exposed to the public internet.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

The research verified nearly 2,000 live, exposed instances, with close to 60% hosted on active customer infrastructure on AWS, Azure, or GCP. These apps were often connected to cloud identities with overly permissive roles. Meanwhile, attackers were not just probing these systems but actively compromising them. Evidence showed roughly 20% of instances contained malicious artifacts like crypto-mining software.

This exploitation provides attackers an initial foothold far beyond the vulnerable application itself. The scope of impact extended to environments associated with prominent Fortune 500 organizations and leading cybersecurity firms. Ultimately, labeling an environment as “training” does not reduce its risk when it’s publicly accessible. The underlying issue stems from excluding these temporary assets from standard security monitoring and lifecycle management.

The presence of active crypto-mining and persistence tooling demonstrates real-world abuse is already occurring at scale. For more details on the methodology and findings, refer to the full research blog or a related live webinar.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Google Targets 2029 Quantum Crypto Deadline, Bitcoin at Risk

Google has set a 2029 deadline to transition its systems to post-quantum cryptography, warning...

Warren Probes MrBeast Over App Coaching Kids on Crypto

Senator Elizabeth Warren sent a 12-page letter to MrBeast and Beast Industries CEO Jeff...

SpaceX, xAI Seeking $75B Ahead of Largest IPO Ever

SpaceX is preparing a historic joint IPO with xAI that could file this week,...

CoinShares Files for New ‘Fear Index’ Bitcoin ETFs

CoinShares has filed to launch three novel ETFs specifically tracking Bitcoin volatility, a first...

Visa Joins Canton as Blockchain Super Validator

Financial giant VISA has joined the blockchain-based Canton Network as a super validator, actively...

Must Read

The Ultimate Guide on How to Understand a Cryptocurrency White Paper

Today, cryptocurrency is a popular buzzword. We hear about it on the news, we read about it on the Internet. Yet, people are reluctant to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading