Attackers in the Dero Cryptojacking operation targeted clusters allowing anonymous access to the Kubernetes API. Anonymous access is controlled by a flag on the kube-apiserver component and most major distributions enable it by default, providing limited access. Disabling anonymous access or removing RBAC rules that allow actions by anonymous users can mitigate security risks.















