logo

Poisoned image to K8s to cloud (Incident)

ID: 2f9e6d5e-6436-57b3-aea7-572e76ffe94c

STIX ID: report--2f9e6d5e-6436-57b3-aea7-572e76ffe94c

Feed Name: Wiz Cloud Threat Landscape

Threat Score
75/100

Date Published: 2023-05-25

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

A Virus Bulletin abstract describes an AWS Kubernetes compromise caused by a supply-chain attack: attackers stole AWS credentials from a DevOps workstation, pushed a poisoned Docker image into a Kubernetes cluster, and used it to move laterally and exfiltrate secrets, tokens, and passwords before defenders detected and contained the activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.