logo

GKE/Gmail vulnerability: notes and tips

ID: 7147c86e-71b8-5606-ab03-62f20aecd252

STIX ID: report--7147c86e-71b8-5606-ab03-62f20aecd252

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2024-01-25

Date Updated: 2026-04-27

Author: James Maskelony

...
...

Security researchers have identified a GKE misconfiguration where the system:authenticated group can include any Google-authenticated account (including external Gmail accounts), which may allow attackers to take control of Kubernetes clusters; researchers estimate up to 250,000 clusters could be at risk. The report emphasizes misconfigurations as a major Kubernetes security problem, recommends auditing role bindings (especially system:anonymous, system:unauthenticated, and system:authenticated) and scoping permissions, and points to investigative resources such as a Kubernetes mind map and cheat sheet for mapping attacker tactics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.