logo

Multiple Flaws in Google Kubernetes Engine Let Attackers Escalate Privileges

ID: 273cb0ec-52e4-5fe9-951f-d9c70d01ac15

STIX ID: report--273cb0ec-52e4-5fe9-951f-d9c70d01ac15

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2024-01-02

Date Updated: 2026-04-22

Author: Eswar

...
...

This report explains how two default-config issues in Google Kubernetes Engine—FluentBit mounting projected service account tokens and Anthos Service Mesh’s Istio CNI DaemonSet keeping excessive privileges—can be chained by an attacker who compromises a FluentBit pod to achieve full cluster takeover; Google patched the configuration issue in mid-December 2023.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.