Someone has been targeting unlocked, internet-connected Docker Engine APIs, and using them to deploy XMRig malware.
Originally appeared here:
Docker API targeted by cryptojacking campaign looking to build mega botnet
Originally appeared here:
Docker API targeted by cryptojacking campaign looking to build mega botnet