#enterprise-cybersecurity — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #enterprise-cybersecurity, aggregated by home.social.
-
The Register: Healthcare cyberattacks hit pacemakers and millions of patient records. “Two major healthcare businesses, Boston Scientific and McKesson, disclosed more details over the weekend about separate cyberattacks that disrupted global operations and resulted in stolen patient data, respectively.”
https://rbfirehose.com/2026/09/03/the-register-healthcare-cyberattacks-hit-pacemakers-and-millions-of-patient-records-2/ -
The Register: Healthcare cyberattacks hit pacemakers and millions of patient records. “Two major healthcare businesses, Boston Scientific and McKesson, disclosed more details over the weekend about separate cyberattacks that disrupted global operations and resulted in stolen patient data, respectively.”
https://rbfirehose.com/2026/09/03/the-register-healthcare-cyberattacks-hit-pacemakers-and-millions-of-patient-records/ -
Schneier On Security: Is Someone Hacking DoD Refrigerators?. “Each service declined to answer questions about how many bases are affected by the outages, referring all questions to the Defense Department. Pentagon officials did not respond to questions.”
https://rbfirehose.com/2026/09/02/schneier-on-security-is-someone-hacking-dod-refrigerators/ -
TechCrunch: CISA confirms hackers targeted over 100 US water systems during July. “U.S. cybersecurity agency CISA said it has observed cyberattacks targeting over 100 internet-exposed systems across the U.S. water and wastewater sector, amid a wave of hacks targeting American critical infrastructure. The number of affected systems provides new context to the scale of the ongoing cyberattacks […]
https://rbfirehose.com/2026/08/30/techcrunch-cisa-confirms-hackers-targeted-over-100-us-water-systems-during-july/ -
The Guardian: Three UK airports hit by cyber-attack with data of 8.7m customers accessed. “Manchester, London Stansted and East Midlands airports have been hit by a cyber-attack in which hackers accessed the data of about 8.7 million customers.”
https://rbfirehose.com/2026/08/29/the-guardian-three-uk-airports-hit-by-cyber-attack-with-data-of-8-7m-customers-accessed/ -
Gizmodo: OpenAI Has to Answer to Alabama on Hugging Face Hack. “OpenAI’s general attitude towards the fact that one of its AI models went rogue and hacked into the systems of the open-source AI platform Hugging Face has been, ‘That’s our bad, but you gotta admit, it’s pretty cool, right?’ The Attorney General of Alabama’s answer to that is a pretty resounding ‘No.’ On Monday, Alabama AG […]
https://rbfirehose.com/2026/08/29/gizmodo-openai-has-to-answer-to-alabama-on-hugging-face-hack/ -
Associated Press: Pro-Russian hackers claim responsibility for major cyberattack on Norway’s public digital services. “A pro-Russian hacker group on Wednesday claimed responsibility for a cyberattack that has affected multiple Norwegian government digital services over the past three days. The cyberattack has been ongoing since Monday, said Are Kvistad, a spokesperson for the Norwegian […]
https://rbfirehose.com/2026/08/27/associated-press-pro-russian-hackers-claim-responsibility-for-major-cyberattack-on-norways-public-digital-services/ -
Reuters: German firms report rising cyber threat from foreign intelligence services, study shows. “German companies are increasingly being targeted by cyberattacks that they suspect are linked to foreign intelligence services, a study by digital industry association Bitkom showed on Wednesday. More than one in three companies hit by cyberattacks, or 37%, said they had attributed at least […]
https://rbfirehose.com/2026/08/26/reuters-german-firms-report-rising-cyber-threat-from-foreign-intelligence-services-study-shows/ -
Troy Hunt: Welcoming the Sri Lankan Government to Have I Been Pwned. “Today, we welcome the 48th government onboarded to Have I Been Pwned’s free gov service: Sri Lanka. Sri Lanka CERT now has access to monitor Sri Lankan government domains against the data in HIBP, helping identify exposed government accounts and respond when they appear in new data breaches.”
https://rbfirehose.com/2026/08/25/troy-hunt-welcoming-the-sri-lankan-government-to-have-i-been-pwned/ -
BBC: Iran-linked hackers behind cyber attack that shut down power plant, reports say. “A small power plant in the UK was shut down during a cyber attack. The government said that at no point was there a risk to the UK’s energy system, but the Department for Energy Security and Net Zero (DESNZ) has contacted power companies to advise them about the risk of cyber attacks.”
https://rbfirehose.com/2026/08/23/bbc-iran-linked-hackers-behind-cyber-attack-that-shut-down-power-plant-reports-say/ -
The Register: Black Hat and DEF CON are AI conferences now, too. “Our cybersecurity editor Jessica Lyons spent last week in Las Vegas for the Black Hat and DEF CON security conferences, and at both events there was only one thing on everyone’s mind: AI agents and their growing threat to cybersecurity defenders.”
https://rbfirehose.com/2026/08/20/the-register-black-hat-and-def-con-are-ai-conferences-now-too/ -
Ars Technica: Terabytes of credentials leaked in massive supply-chain attack. “Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines AI-driven software development. Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities […]
https://rbfirehose.com/2026/08/14/ars-technica-terabytes-of-credentials-leaked-in-massive-supply-chain-attack/ -
CISA: CISA Unveils New Cybersecurity Resources for K-12 Schools and Districts. “The Cybersecurity and Infrastructure Security Agency (CISA) today released the K-12 Cybersecurity Foundations Resource Package, a comprehensive collection of guides, videos and supplemental materials to help K‑12 schools and districts prevent, mitigate and respond to prevalent cyber threats.”
https://rbfirehose.com/2026/08/14/cisa-cisa-unveils-new-cybersecurity-resources-for-k-12-schools-and-districts/ -
Associated Press: Anthropic says its AI models hacked 3 organizations during testing. “Anthropic said its artificial intelligence models hacked into three other organizations during testing, just days after ChatGPT maker OpenAI raised concerns over AI controls after it disclosed its rogue models hacked another company.”
https://rbfirehose.com/2026/08/02/associated-press-anthropic-says-its-ai-models-hacked-3-organizations-during-testing/ -
Reuters: Minnesota IT officials disclose ‘coordinated cyberattack’ at more than 30 local water systems. “The attacks are similar to a wave of cyber intrusions against U.S. water infrastructure that officials have in the past attributed to Iranian-affiliated hackers, raising concerns about the vulnerability of local utilities that serve millions of people.”
https://rbfirehose.com/2026/07/31/reuters-minnesota-it-officials-disclose-coordinated-cyberattack-at-more-than-30-local-water-systems/ -
How to Stay Protected
XMRig Malware Campaigns Target Businesses
Cybersecurity threats continue to evolve, and one of the most persistent threats facing businesses today involves cybercriminals abusing the popular XMRig mining software. While XMRig is a legitimate, open-source cryptocurrency miner used by many enthusiasts to mine Monero (XMR), attackers frequently modify or secretly install it on corporate computers to generate profits without the owner’s knowledge.
In this article, we’ll explain how XMRig is being misused in corporate environments, the risks to businesses, how these attacks work, and the best practices to prevent them.
What Is XMRig?
XMRig is a free and open-source CPU and GPU miner designed primarily for mining Monero (XMR). It is widely respected within the cryptocurrency community because it is efficient, actively maintained, and available for Windows, Linux, and macOS.
By itself, XMRig is not malware. However, cybercriminals often bundle modified versions of XMRig with malicious software or deploy it after compromising a computer.
Why Are Businesses Being Targeted?
Corporate environments provide an attractive opportunity for attackers because they often contain:
- High-performance desktop computers
- Powerful servers
- Multiple workstations
- Cloud infrastructure
- Continuous internet connectivity
Instead of mining cryptocurrency on their own hardware, attackers infect company devices and secretly use the organisation’s computing power.
The result is free cryptocurrency mining at the company’s expense.
How XMRig Malware Gets Installed
Most unauthorised XMRig installations begin after another security weakness has already been exploited.
Common infection methods include:
- Phishing emails containing malicious attachments
- Fake software downloads
- Exploitation of unpatched vulnerabilities
- Weak Remote Desktop Protocol (RDP) passwords
- Stolen administrator credentials
- Trojan malware that downloads additional payloads
Once attackers gain access, they silently install XMRig and configure it to connect to their own mining pools.
Warning Signs of an XMRig Infection
Many organisations discover mining malware only after performance problems become noticeable.
Common symptoms include:
- Constantly high CPU usage
- Increased electricity consumption
- Slow computers
- Loud cooling fans
- Servers running hotter than normal
- Unknown scheduled tasks
- Unexpected outbound network traffic
- Security software being disabled
Some attackers even configure XMRig to stop mining whenever a user opens Task Manager, making detection more difficult.
Business Impact
Although cryptojacking usually does not encrypt files like ransomware, it can still cause significant operational issues.
Potential consequences include:
Reduced Productivity
Employees experience slower computers, affecting daily work.
Higher Operating Costs
Mining consumes CPU resources and electricity around the clock.
Hardware Wear
Continuous high CPU usage can shorten the lifespan of processors, cooling systems, and power supplies.
Security Risks
An XMRig infection often indicates that attackers already have unauthorised access to the network, meaning sensitive business data may also be at risk.
How Organisations Can Protect Themselves
Preventing cryptojacking requires multiple layers of security.
Keep Systems Updated
Install security updates for Windows, Linux, browsers, and all business software as soon as practical.
Use Endpoint Protection
Modern antivirus and endpoint detection solutions can identify suspicious mining behaviour before it becomes widespread.
Enable Multi-Factor Authentication
Protect administrator accounts and remote access services with MFA wherever possible.
Monitor CPU Usage
Investigate unexplained spikes in processor utilisation, especially outside business hours.
Restrict Administrative Privileges
Limit local administrator permissions to reduce the impact of compromised accounts.
Educate Employees
Regular cybersecurity awareness training helps staff recognise phishing emails and other social engineering attacks.
Is XMRig Dangerous?
The software itself is completely legitimate.
The danger comes from unauthorised installation and misuse by attackers.
Many security vendors detect unauthorised XMRig deployments because they are commonly associated with cryptojacking campaigns rather than because the software itself is malicious.
Best Practices for IT Teams
Organisations should adopt a proactive security strategy by:
- Regularly auditing endpoints
- Monitoring unusual network connections
- Reviewing scheduled tasks and startup entries
- Enforcing least-privilege access
- Conducting vulnerability scans
- Backing up critical business data
- Implementing continuous security monitoring
Early detection significantly reduces the financial and operational impact of mining malware.
Final Thoughts
Cryptocurrency mining software like XMRig serves legitimate purposes for individuals and organisations that choose to mine digital assets. However, when cybercriminals secretly deploy XMRig on corporate systems, it becomes part of a cryptojacking attack that wastes resources, increases costs, and may signal a broader security compromise.
Businesses should combine strong cybersecurity practices, employee awareness, regular patching, and continuous monitoring to minimise the risk of unauthorised mining software running within their networks.
By understanding how these attacks operate and responding quickly to suspicious activity, organisations can better protect their infrastructure, maintain productivity, and reduce the likelihood of future compromises.
Frequently Asked Questions
Is XMRig malware?
No. XMRig is legitimate open-source cryptocurrency mining software. It only becomes part of malicious activity when attackers install it without permission.
What cryptocurrency does XMRig mine?
It is primarily designed to mine Monero (XMR) using the RandomX algorithm.
Can antivirus detect XMRig?
Many security products detect unauthorised XMRig installations because they are commonly used in cryptojacking attacks.
How can I tell if my computer is mining cryptocurrency?
Persistent high CPU usage, overheating, increased fan noise, slow performance, and unexplained network connections can all indicate possible cryptojacking.
#Technology #ai #businessSecurity #corporateSecurity #cpuMining #cryptoMalware #cryptocurrencyMining #cryptojacking #cyberSecurity #cyberThreats #cyberSecurity #cybersecurity #dataProtection #endpointSecurity #enterpriseCybersecurity #ITSecurity #LinuxSecurity #malwareDetection #malwareProtection #miningMalware #Monero #MoneroMiner #MoneroMining #networkSecurity #phishingAttacks #RandomX #ransomware #security #securityAwareness #serverSecurity #WindowsSecurity #XMRig #XMRigMalware #XMRigMiner -
Ars Technica: Pay up or not? Ransomware surge has victims facing tough choices.. “This has been powered by the rise of malicious AI hacking tools such as WormGPT, FraudGPT and BruteForceAI, according to Dave Spillane, systems engineering director at Fortinet, who notes that confirmed ransomware victims rose 389 percent year-on-year in 2025, from around 1,600 in 2024 to 7,831 globally.”
https://rbfirehose.com/2026/07/22/ars-technica-pay-up-or-not-ransomware-surge-has-victims-facing-tough-choices/ -
Associated Press: OpenAI says its AI technology acted on its own in an ‘unprecedented’ hack of another company. “ChatGPT maker OpenAI said Tuesday that its artificial intelligence system hacked into another AI company on its own in what the company called an ‘unprecedented cyber incident.'”
https://rbfirehose.com/2026/07/22/associated-press-openai-says-its-ai-technology-acted-on-its-own-in-an-unprecedented-hack-of-another-company/ -
Hugging Face: Security incident disclosure — July 2026. “Earlier this week, we detected and responded to an intrusion into part of our production infrastructure. This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system – and we detected and dissected it largely with AI of our own.”
https://rbfirehose.com/2026/07/19/hugging-face-security-incident-disclosure-july-2026/ -
TechCrunch: Another massive data breach exposed millions of driver’s license numbers. “U.S. insurance provider AssuranceAmerica has confirmed a data breach affecting the personal information and driver’s license numbers of 6.9 million people, making it the largest known spill of Americans’ driver’s license information this year.”
https://rbfirehose.com/2026/07/10/techcrunch-another-massive-data-breach-exposed-millions-of-drivers-license-numbers/ -
The Register: Moody Bible Institute breach leaves 2.3M accounts needing salvation, says cyber expert. “Data on more than 2.3 million people associated with Moody Bible Institute (MBI) has been exposed online after the Christian college was targeted by ShinyHunters. The attack was first disclosed by MBI in June, and the extortion crew later leaked the stolen data. Have I Been Pwned has since […]
https://rbfirehose.com/2026/07/09/the-register-moody-bible-institute-breach-leaves-2-3m-accounts-needing-salvation-says-cyber-expert/ -
Gizmodo: Hackers Steal Funds From Polymarket Users, Potentially Millions. “A third-party vendor has been compromised, and some Polymarket users have lost money to hackers, according to a tweet from the betting site. The company has not confirmed how much was lost, though independent monitors on X suggest it could be around $3 million.”
https://rbfirehose.com/2026/06/28/gizmodo-hackers-steal-funds-from-polymarket-users-potentially-millions/ -
BBC: How 100 hospitals switched to pen and paper to defeat a national cyber-attack. “Medical staff had to switch to pen and paper, improvising workarounds to protect patients while IT teams scrambled and the national cyber response centre tried to find out how the hackers had got in – and how they could stop them.”
https://rbfirehose.com/2026/06/25/bbc-how-100-hospitals-switched-to-pen-and-paper-to-defeat-a-national-cyber-attack/ -
Cloudflare: Celebrating 12 years of Project Galileo. “Twelve years ago this month, Cloudflare launched an ambitious project built on a simple idea: people shouldn’t be knocked offline just because someone more powerful disagrees with them. Today, Project Galileo provides free access to cybersecurity services to more than 3,400 websites belonging to journalists, human rights defenders, and […]
https://rbfirehose.com/2026/06/20/cloudflare-celebrating-12-years-of-project-galileo/ -
Bleeping Computer: FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.. “A newly discovered data leak dubbed ‘FortiBleed’ has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs at organizations worldwide.”
https://rbfirehose.com/2026/06/17/bleeping-computer-fortibleed-leak-exposes-fortinet-vpn-credentials-for-73000-devices/ -
TechCrunch: The FBI built its own replica small town to simulate real-world cyberattacks.”The Federal Bureau of Investigation is pulling back the curtain on a 22,000 square-foot replica town on its Huntsville, Alabama campus that it built to train law enforcement in simulating and investigating real-world cyberattacks.”
https://rbfirehose.com/2026/06/15/techcrunch-the-fbi-built-its-own-replica-small-town-to-simulate-real-world-cyberattacks/ -
PBS: Why a surge of election-related websites could spell rising cyber threats for the midterms. “A new report, first reported by PBS News, warns that November’s midterm elections in the United States will drive ‘elevated’ cyber threats to political organizations, fundraising and media platforms, and that some of the groundwork for election misinformation and disinformation likely is already […]
https://rbfirehose.com/2026/06/01/pbs-why-a-surge-of-election-related-websites-could-spell-rising-cyber-threats-for-the-midterms/ -
The Register: MyPillow must decide whether to be firm or soft as ransomware crims demand pay. “Crims found the soft spot in the company’s security. MyPillow, the US-based bedding brand founded by election conspiracy theorist Mike Lindell, has been listed by Play ransomware extortionists as an alleged victim.”
https://rbfirehose.com/2026/05/29/the-register-mypillow-must-decide-whether-to-be-firm-or-soft-as-ransomware-crims-demand-pay/ -
TechCrunch: NYC Health + Hospitals says hackers stole medical data and fingerprints during breach affecting at least 1.8 million people. “New York public health provider NYC Health + Hospitals says a months-long data breach that allowed hackers to steal personal data, medical records, and fingerprints scans affects at least 1.8 million people.”
https://rbfirehose.com/2026/05/21/techcrunch-nyc-health-hospitals-says-hackers-stole-medical-data-and-fingerprints-during-breach-affecting-at-least-1-8-million-people/ -
Associated Press: Google disrupts hackers using AI to exploit an unknown weakness in a company’s digital defense. “Google said Monday that it had disrupted a criminal group’s attempt to use artificial intelligence to exploit another company’s previously unknown digital vulnerability, adding to heightened worries across government and private industry about AI’s risks for cybersecurity.”
https://rbfirehose.com/2026/05/14/associated-press-google-disrupts-hackers-using-ai-to-exploit-an-unknown-weakness-in-a-companys-digital-defense/