build2 distinct publishers
Your test grid is an RCE surface: SeleniumGreed turns exposed Selenium hubs into miners
Wiz says attackers are using the WebDriver API's documented remote-command features to plant a modified XMRig on internet-facing Selenium Grid nodes. Authentication is off by default.
Reality
- Evidence74
- Adoption