Several Elasticsearch Databases Attacked for Ransom
Secureworks spotted a new campaign targeting vulnerable Elasticsearch databases to replace their indexes with a ransom note; a total ransom of $280,000 has been demanded. The attackers have used an automated script to parse unprotected databases, wipe out their data, and add the ransom note. Admins should set up MFA for authorized users and limit access to only those who need it.