Multiple Flaws in Google Kubernetes Engine Let Attackers Escalate Privileges
ID: 273cb0ec-52e4-5fe9-951f-d9c70d01ac15
STIX ID: report--273cb0ec-52e4-5fe9-951f-d9c70d01ac15
Feed Name: GBHackers
Threat Score
This report explains how two default-config issues in Google Kubernetes Engine—FluentBit mounting projected service account tokens and Anthos Service Mesh’s Istio CNI DaemonSet keeping excessive privileges—can be chained by an attacker who compromises a FluentBit pod to achieve full cluster takeover; Google patched the configuration issue in mid-December 2023.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
