Hackers Exploit Kubernetes Misconfigurations to Move From Containers to Cloud Accounts
ID: 4c2292a0-d4a0-50e8-80a5-6a5a424b5fa7
STIX ID: report--4c2292a0-d4a0-50e8-80a5-6a5a424b5fa7
Feed Name: cybersecurityNews.com
This report describes a surge in Kubernetes-focused attacks where adversaries exploit container misconfigurations and steal service account tokens to move from compromised pods into cloud accounts; it cites a Lazarus-linked intrusion against a cryptocurrency exchange that used a developer’s privileged session to deploy a malicious pod, harvest a high-privilege JWT, and steal millions, and also documents active exploitation of CVE-2025-55182 (React2Shell) leading to container code execution and cloud pivots. The report emphasizes enforcing least-privilege RBAC, using short-lived projected tokens, enabling Kubernetes audit logs, and deploying runtime detection to prevent escalation from cluster to cloud.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
